From MediaWiki.org
Jump to: navigation, search
MediaWiki extensions manualManual:Extensions
Crystal Clear action run.png

Release status:Extension status beta

ImplementationTemplate:Extension#type User rights, Special page, Page action
DescriptionTemplate:Extension#description An HMAC based One Time Password extension, providing two-factor authentication.
Author(s)Template:Extension#username Ryan Lane
Latest versionTemplate:Extension#version 0.2.2 (2017-01-01)
MediaWikiTemplate:Extension#mediawiki 1.25+
Database changesTemplate:Extension#needs-updatephp Yes
LicenseTemplate:Extension#license GNU General Public License 2.0 or later
Hooks usedTemplate:Extension#hook

Translate the OATHAuth extension if it is available at translatewiki.net

Check usage and version matrix.


Open tasks · Report a bug

The OATHAuth extension is an TOTP implementation. It provides two-factor authentication via something you have (your phone or desktop client) and something you know (your user name/password). Client support is available for most feature phones, smartphones and desktops (see en:Time-based One-time Password Algorithm#Client_implementations).


  • Download and place the file(s) in a directory called OATHAuth in your extensions/ folder.
  • Add the following code at the bottom of your LocalSettings.php:
    wfLoadExtension( 'OATHAuth' );
  • Run the update script which will automatically create the necessary database tables that this extension needs.
  • YesY Done - Navigate to Special:Version on your wiki to verify that the extension is successfully installed.

To users running MediaWiki 1.24 or earlier:

The instructions above describe the new way of installing this extension using wfLoadExtension() If you need to install this extension on these earlier versions (MediaWiki 1.24 and earlier), instead of wfLoadExtension( 'OATHAuth' );, you need to use:

require_once "$IP/extensions/OATHAuth/OATHAuth.php";

Resetting a user token[edit]

In the event that a user both loses their token generator AND the recovery tokens; two-factor authentication may be removed from the user by deleting their row from the oathauth_users database table.



  • Initial version
  • Missing functionality to act as a standalone extension, currently reuses a hook in LdapAuthentication. Standalone support to come in next version.

See also[edit]