You are located in service: Multi-factor authentication (MFA)

Authenticator app e.g. for Smartphone, Laptop or Desktop (TOTP)

Authenticator app e.g. for Smartphone, Laptop or Desktop (TOTP)

guide

This page describes how to set up an authenticator app for multi-factor authentication (MFA).

An authenticator app generates a new one-time password every 30 seconds.

Follow these steps to set up your app:

  1. Download authenticator app
  2. Set up authenticator app
  3. Login with authenticator app

In this guide, we use the 2FAS-App, but you can use a different authenticator app.


1. Download authenticator app

Step 1
Open the app store on your device.

Step 2
Download an authenticator app, such as:

2. Set up authenticator app

Step 1
Open the Token Manager (opens in new tab).

Step 2
Log in via RWTH Single Sign-On (username format ab123456).

Step 3
Click Create.

Overview of the Token Manager in SelfService.

Step 4
Under Type of Token, select Authenticator app e.g. for smartphone (TOTP).

Step 5
Click Next.

Select the type of token.

Step 6
Enter a name for your app under Description (e.g. Authenticator App).

Optional
Select Advanced Options to change the length of your security code and hash algorithm.

Step 7
Click Create.

Input field for the key description.

A QR code appears.

QR code or token secret for setting up the token in an authenticator app.

Step 8
Open your authenticator app.

Please note
We have taken screenshots in the 2FAS app for this guide. If you are using a different app, the process may be slightly different.

Step 9
Tap the plus symbol.

Home screen of the 2FAS authenticator app.

Step 10
Scan the QR code using the app.

Alternatively, you can click Token secret below the QR code. A code will be displayed. Copy this code in the app under Enter secret key.

Setup window of the 2FAS authenticator app with the camera open.

A code appears in the app.

Confirmation of the 2FAS authenticator app setup.

Step 11
Enter this code in the Token Manager under Security code.

Step 12
Click Finish.

Input field in the Token Manager for token confirmation.

You have successfully set up your authenticator app.

 

Note

Unverified tokens remain unconfirmed and are not stored in Token Manager. They cannot be used when logging in with single sign-on.

3. Login with authenticator app

When you are prompted to enter a one-time password, open the Authenticator app.

Copy the password displayed under RWTH Aachen University and paste it into the input field.

The passwords are valid for 30 seconds. If a code expires before you have entered it, simply use the next one.


Additional Information

last changed on 08/11/2026

How did this content help you?

(opens in new tab)
This work is licensed under a Creative Commons Attribution - Share Alike 3.0 Germany License (opens in new tab)