We're on Product Hunt today! Leave a comment

Add to Chrome

Zoho authenticator app

Zoho multi-factor authentication does not require Zoho’s own OneAuth app: its “OTP Authenticator” mode works with any standard authenticator, including one in your browser. Go to accounts.zoho.com → Multi-Factor Authentication → “Set up Now” under OTP Authenticator, and scan the QR code from the screen with the Authenticator extension.

One Zoho account signs you in to every Zoho app you use — Mail, CRM, Books, Desk — so a stolen password opens all of them at once. With multi-factor authentication on, Zoho also asks for the code from your authenticator. Zoho promotes its OneAuth app, but its OTP Authenticator mode is there for anyone who would rather use the authenticator they already have.

Turn on the OTP authenticator in Zoho

If your organization manages your Zoho account, its admin may enforce MFA and choose which modes are allowed — if “OTP Authenticator” is missing or cannot be set up, the policy does not allow it. If you already use another MFA mode, set the authenticator as your default afterwards with “MAKE PRIMARY” next to OTP authenticator.

  1. Sign in at accounts.zoho.com on your computer.
  2. Click “Multi-Factor Authentication” in the left menu.
  3. Find “OTP Authenticator” among the MFA modes — Zoho’s own OneAuth app is listed separately.
  4. Click “Set up Now” under “OTP Authenticator”. Zoho shows a QR code and the secret.
  5. Leave the QR code on the screen and add it to the extension as described below — or copy the secret for manual entry — then click “Next”, enter the code and click “Verify”.
Zoho’s own instructions

Add Zoho to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Zoho page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Zoho and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Zoho confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Zoho’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Generate your Zoho backup verification codes

Zoho does not hand out backup codes on its own — generate them: in Multi-Factor Authentication click “MFA Recovery Options”, then “Generate new codes”, and copy or download them. They are 12-digit codes, shown only once, each works once, and a new set cancels the old one. Keep them somewhere other than this computer.

The code is not accepted?

Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.

If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Do I need Zoho OneAuth?
No. OneAuth is one of Zoho’s MFA modes; “OTP Authenticator” is another, and Zoho names Google Authenticator, Microsoft Authenticator and Authy for it. The Authenticator extension produces the same standard codes in Chrome and reads the QR code straight off the Zoho page.
My mail app stopped signing in after I turned on MFA.
Mail programs such as Outlook or Thunderbird cannot ask for a code, and often report it as a wrong password. Generate an application-specific password in your Zoho account and enter it in the mail program instead of your normal password.
What if I lose access to my authenticator?
At the MFA prompt click “Can’t access your device?” (or “Problem signing in?” first) and use a backup verification code. Without one, write to support@zohoaccounts.com: Zoho verifies your identity and gives you a one-time code. Once in, set the authenticator up again with “Change Configuration”.
Why does Zoho say my code is wrong?
Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension, click “Change Configuration” under OTP authenticator and add the new QR code.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free