Totp
TOTP-based OTP verification for sensitive operations (env vars, gateway restarts, backup deletions,
- Rating
- 3.8 (104 reviews)
- Downloads
- 1,627 downloads
- Version
- 1.0.0
Overview
TOTP-based OTP verification for sensitive operations (env vars, gateway restarts, backup deletions, critical config.
Complete Documentation
View Source →
TOTP Verification Skill
Secure OTP verification using TOTP (Time-based One-Time Password) for sensitive operations.
Purpose
Protect access to:
.envvariablesopenclaw.jsonconfiguration- Gateway restarts
- Backup deletions
- Critical configuration changes
- External API key operations
Setup
- Install dependencies:
npm install
- Generate secret and QR:
npm run generate
node scripts/generate-secret.js MyService myuser
- Send the QR image (
qr.png) to the user, then delete it immediately:
rm qr.png
- Set TOTP_SECRET in
.env:
TOTP_SECRET=YOUR_BASE32_SECRET_HERE
- Configure Google Authenticator/Authy with the generated secret or QR.
Usage
When a sensitive operation is requested:
- Agent: "Please provide your OTP"
- User: Provides 6-digit code from authenticator app
- Agent: Runs verification:
TOTP_SECRET=$TOTP_SECRET node scripts/verify.js 123456
- If valid (exit 0): Proceed with operation
- If invalid (exit 1): Deny access
Files
scripts/generate-secret.js- Generate new TOTP secret and QRscripts/verify.js- Verify OTP tokens (window:2 = 1 minute tolerance)SKILL.md- This documentation
Security Notes
- Window: 2 (1 minute tolerance) for time drift
- Algorithm: SHA1
- Digits: 6
- Period: 30 seconds
- Secret: Base32 encoded, stored in
.envasTOTP_SECRET
Integration
This skill should be integrated into the agent's decision flow when:
- User requests
.envvariables - User requests
openclaw.jsoncontents - User requests gateway restart
- User requests backup deletion
- Any operation marked as "critical"
Installation
openclaw install totp
Tags
Quick Info
Ready to Install?
Get started with this skill in seconds
Related Skills
4claw
4claw — a moderated imageboard for AI agents.
Aap Passport
Agent Attestation Protocol - The Reverse Turing Test.
Acestep Lyrics Transcription
Transcribe audio to timestamped lyrics using OpenAI Whisper or ElevenLabs Scribe API.
Adaptive Suite
A continuously adaptive skill suite that empowers Clawdbot.