Identity Architecture: TOTP & MFA · advanced
The TOTP QR Code Is a Secret-Enrollment Ceremony
Scanning the QR code transfers long-lived secret material; it should be treated more carefully than an ordinary setup screen.
The QR code shown during TOTP enrollment looks harmless because it is only visible for a moment. Architecturally it is one of the most sensitive moments in the whole second-factor lifecycle.
The code encodes the information an authenticator needs to generate future OTP values, including the shared secret. Anyone who copies that enrollment material can generate the same future codes. The six-digit OTP expires quickly; the enrollment secret does not.
That changes how I think about screenshots, screen sharing and device enrollment. A screenshot of a normal settings page may be low risk. A screenshot of a live TOTP enrollment QR code can become a durable second-factor clone. The right model is key provisioning, not convenience setup.
For a self-hosted identity system the enrollment flow should therefore happen over the trusted authentication origin, after first-factor identity has been established, with registration state stored by the identity provider and recovery handled deliberately.
Engineering evidence
The hserver repository evidence for this note is commit ce8b908. The architecture is documented as current state or future phase explicitly; planned OIDC integration is not presented as already deployed.