• Most sites that use 2 step auth don’t ask for the OTP password in the login form. Once you login, they ask (if you have it enabled) for it. Take gmail, for example.

    I find this more user friendly, because users that don’t have it enabled are not confused by that field that don’t know what to enter (empty is fine, but it is confusing if they don’t know what it is)

    So, can you consider asking for the OTP password after the username/password have already been verified?

    https://www.ads-software.com/plugins/wp-google-authenticator/

  • The topic ‘Display OTP code after validating username/password’ is closed to new replies.