We're on Product Hunt today! Leave a comment

Add to Chrome

Heroku authenticator app in your browser

Heroku requires multi-factor authentication, and any standard authenticator app satisfies it — including one in your browser. In the Dashboard open Account Settings → Setup Multi-Factor Authentication → Add One Time Password Generator, and scan the QR code from the screen with the Authenticator extension.

A Heroku account deploys code, holds config vars full of API keys and database credentials, and runs up the bill — exactly what attackers look for. That is why Salesforce requires multi-factor authentication of every Heroku user. Salesforce Authenticator is one way to meet it; a time-based code from any authenticator app is another, and it needs no phone signal.

Add an authenticator app to Heroku

New Heroku accounts are asked to turn on multi-factor authentication as they are created — then the setup opens on its own, and you pick the one-time password generator there. If your team signs in to Heroku through single sign-on, multi-factor authentication is set up at that identity provider instead, and these steps do not apply.

  1. Sign in to the Heroku Dashboard on your computer.
  2. Open “Account Settings”.
  3. Select “Setup Multi-Factor Authentication” — or “Manage Multi-Factor Authentication” if a verification method is already on.
  4. Click “Add One Time Password Generator”.
  5. Heroku shows a QR code. Leave it on the screen and add it to the extension as described below — then enter the code from the extension and click “Connect”.
Heroku’s own instructions

Add Heroku to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Heroku page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Heroku and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Heroku confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Heroku’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Generate your 10 Heroku recovery codes

Recovery codes are a verification method of their own: on the same multi-factor authentication page choose “Add Recovery Codes”, and Heroku shows 10 single-use codes. Save them somewhere other than this computer — each stays valid until it is used, and you can generate a new set at any time. To sign in with one, click “Didn’t receive a notification?” → “Choose Another Verification Method” → “Recovery Codes”.

The code is not accepted?

Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.

If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Do I need Salesforce Authenticator for Heroku?
No. Salesforce Authenticator sends push notifications, but Heroku equally accepts a one-time password generator — any app that produces standard time-based codes. Heroku names Google Authenticator, Microsoft Authenticator and Authy; the Authenticator extension works the same way and reads the QR code straight off the Dashboard.
How do I log in to the Heroku CLI with multi-factor authentication?
Run heroku login: it opens the browser, where you sign in to the Dashboard and enter the code from the extension. The --interactive option, which asks for the password in the terminal, cannot be used with multi-factor authentication.
What if I lose access to my authenticator?
Sign in with a recovery code, then set the authenticator up again. In a Heroku Enterprise Account, an admin can send you a temporary verification code with “Send MFA Recovery Token” on the account’s Access tab. Otherwise contact Heroku Support, which may ask for extra information to make sure it is you.
Why does Heroku say my code is wrong?
Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension, delete the one-time password generator under Manage Multi-Factor Authentication, and add it again.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free