We're on Product Hunt today! Leave a comment

Salesforce authenticator app

Salesforce multi-factor authentication accepts any authenticator app that supports TOTP, not only Salesforce Authenticator — including one in your browser. In your personal settings open Advanced User Details, click “Connect” next to “App Registration: One-Time Password Authenticator”, and scan the QR code from the screen with the Authenticator extension.

A Salesforce login opens your company’s customer records, deals, cases and reports — data that can be exported in minutes by whoever has your password. Organizations turn on multi-factor authentication so that a stolen or reused password alone is not enough. Salesforce Authenticator is Salesforce’s own app with push approvals; the one-time password option takes a standard code, so it can live on the computer you work in Salesforce on.

Connect an authenticator app to Salesforce

Your Salesforce administrator decides how your organization signs in. If you sign in through your company’s own login (Okta, Microsoft Entra ID, Google), the second step belongs to that system, not to Salesforce. Salesforce emails you whenever a new verification method is added to your account.

  1. Sign in to Salesforce on your computer and open your personal settings — click your profile picture and choose “Settings”.
  2. In the Quick Find box, enter “Advanced User Details” and select it. If nothing comes up, search for “Personal Information” instead.
  3. Find “App Registration: One-Time Password Authenticator” and click “Connect”. Salesforce may ask you to log in again first.
  4. When Salesforce shows a QR code, leave that page open and add it to the extension as described below — or click “I Can't Scan the QR Code” to see a key for manual entry. Then type the code from the extension into “Verification Code” and click “Connect”.
Salesforce’s own instructions

Add Salesforce to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Salesforce page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Salesforce and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Salesforce confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Salesforce’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Plan a way back into Salesforce

Salesforce does not give users backup codes. If you lose your authenticator, your Salesforce administrator can generate a temporary verification code for you — it works for 1 to 24 hours, as the admin sets — and disconnect the old app, so that Salesforce asks you to register a new method at the next login. Salesforce recommends registering more than one verification method; the extension’s automatic backups keep a reinstall from costing you the codes.

The code is not accepted?

Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.

Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Do I have to use Salesforce Authenticator?
No. Salesforce Authenticator adds push approvals, but Salesforce accepts codes from any authenticator app that supports TOTP — Google Authenticator, Microsoft Authenticator, Authy, or the Authenticator extension in Chrome, which reads the QR code straight off the Salesforce page.
Salesforce keeps asking me to approve on Salesforce Authenticator. How do I use the code?
Salesforce offers your methods in a fixed order — Salesforce Authenticator first, then built-in authenticators and security keys, then third-party authenticator apps. If Salesforce Authenticator is also connected, choose the option to use a different verification method on the login screen and enter the code from the extension.
What if I lose access to my authenticator?
Use another verification method if you registered one. Otherwise ask your Salesforce administrator for a temporary verification code and to disconnect the lost authenticator; at your next login Salesforce asks you to connect a new one. Restoring the extension’s automatic backups on a new computer keeps the same codes working.
Can I use Salesforce MFA without a phone?
Yes. Salesforce’s help says you can install a third-party authenticator app on your mobile device or computer, and that a desktop app can take the key instead of the QR code. The Authenticator extension does either in Chrome, on the computer you already use for Salesforce.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free