<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Totp on WebNotes</title><link>https://v2.webnotes.in/tags/totp/</link><description>Recent content in Totp on WebNotes</description><generator>Hugo</generator><language>en-IN</language><lastBuildDate>Sat, 20 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://v2.webnotes.in/tags/totp/index.xml" rel="self" type="application/rss+xml"/><item><title>How to disable TOTP on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-disable-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-disable-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;To disable TOTP on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
, log in, open My profile then Password &amp;amp; security, click Disable external TOTP, enter your Kite login password, and click Disable; the account then reverts to the &lt;a href="https://v2.webnotes.in/sms-otp/" rel="nofollow"&gt;SMS OTP&lt;/a&gt;
 as its second factor.&lt;/strong&gt; You cannot switch the second factor off entirely, because two-factor authentication on a trading login is mandated by the exchanges and SEBI.&lt;/p&gt;
&lt;p&gt;This is the point most people miss. &amp;ldquo;Disable TOTP&amp;rdquo; does not mean &amp;ldquo;log in with just a password.&amp;rdquo; It means swap the time-based app code back for the text-message code. One second factor always remains. Zerodha&amp;rsquo;s support pages are explicit that the OTP step at login cannot be eliminated, only changed in form.&lt;/p&gt;</description></item><item><title>How to fix Kite logging out when switching apps</title><link>https://v2.webnotes.in/how-to-fix-kite-logout-switching-apps/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-fix-kite-logout-switching-apps/</guid><description>&lt;p&gt;The &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 app logs you out when you switch to another app, such as an authenticator app to copy a time-based one-time password (TOTP), because your device is in power-saving mode or is preventing Kite from running in the background; the operating system kills the backgrounded app and drops your session. Per Zerodha&amp;rsquo;s own support article, this is a power-management behaviour, not a deliberate security lock that triggers on app switch. The fix is to stop the OS from suspending Kite: turn off power saving, exempt Kite from battery optimisation, or sidestep the switch entirely by using device-lock biometric login instead of TOTP.&lt;/p&gt;</description></item><item><title>How to fix the Invalid TOTP error on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-fix-invalid-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-fix-invalid-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;The Invalid TOTP error on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 is a clock problem, not a wrong code: Kite rejects the &lt;a href="https://v2.webnotes.in/how-to-set-up-totp-zerodha/"&gt;TOTP&lt;/a&gt;
 when the clock on the device running your authenticator does not match network time, so set that phone to automatic or network-provided time and enter a fresh six-digit code.&lt;/strong&gt; TOTP is time-based; a drift of even a minute makes the app compute the code for the wrong 30-second window, and Kite refuses it.&lt;/p&gt;
&lt;p&gt;This is the single most common cause, and it is also the least obvious one, because the code on screen looks perfectly valid. It is valid, for a moment that has already passed or not yet arrived. The fix is to correct the clock on the device that generates the code, which is the phone holding Google Authenticator or Authy, not the computer you are logging in from.&lt;/p&gt;</description></item><item><title>How to log in to Zerodha when your mobile is lost</title><link>https://v2.webnotes.in/how-to-login-mobile-lost-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-login-mobile-lost-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;If your registered mobile is lost, you regain Kite access by switching your second factor from SMS OTP to a TOTP authenticator app, which generates the 6-digit login code on any device without an SMS.&lt;/strong&gt; SMS-based two-factor authentication depends on the SIM in your hand; a lost phone breaks it. The fix is a &lt;a href="https://v2.webnotes.in/kite-app-code/"&gt;TOTP authenticator&lt;/a&gt;
, set up during a password reset that you verify by email rather than SMS. This guide walks that reset-and-switch flow, the change-of-mobile route to restore your number, and the harder case where both your mobile and email are gone.&lt;/p&gt;</description></item><item><title>How to recover a lost TOTP on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-recover-lost-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-recover-lost-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;If you lost the phone holding your authenticator, deleted the app, or wiped the device, recover access on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 by clicking Forgot user ID or password? on the login page; verify with your user ID, PAN, and an OTP to your registered email or mobile, set a new password, then re-enrol TOTP under Method 2: External authenticator and scan a fresh QR code.&lt;/strong&gt; The standard reset is self-service and free; no support ticket is needed unless you have also lost access to both your registered email and mobile.&lt;/p&gt;</description></item><item><title>How to remove the temporary OTP on Kite</title><link>https://v2.webnotes.in/how-to-remove-temporary-otp-kite/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-remove-temporary-otp-kite/</guid><description>&lt;p&gt;&lt;strong&gt;You cannot remove the temporary OTP step on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
, because NSE and &lt;a href="https://v2.webnotes.in/sebi/"&gt;SEBI&lt;/a&gt;
 require a second authentication factor on every trading login; what you can do is switch the temporary OTP from an SMS-delivered code to an authenticator-generated &lt;a href="https://v2.webnotes.in/how-to-set-up-totp-zerodha/"&gt;TOTP&lt;/a&gt;
, under My profile then Password &amp;amp; security.&lt;/strong&gt; The OTP step itself is mandatory and stays; only its form is yours to choose.&lt;/p&gt;
&lt;p&gt;The phrase &amp;ldquo;temporary OTP&amp;rdquo; describes the time-limited one-time password Kite asks for after your password at each login. It is temporary in the literal sense: each code is valid for a short window, about 30 seconds for an authenticator code, then expires. People searching to &amp;ldquo;remove&amp;rdquo; it usually mean one of two things: they want to stop the SMS-delivered OTP and use something smoother, or Zerodha issued them a one-off temporary access after a lockout and they want to know how to get back to a normal login. This guide covers both.&lt;/p&gt;</description></item><item><title>How to set up TOTP on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-set-up-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-set-up-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;TOTP, or time-based one-time password, is a six-digit code that an authenticator app on your phone generates offline and refreshes every 30 seconds; on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 you enable it under My profile, Password &amp;amp; security, Enable external TOTP, then scan a QR code with &lt;a href="https://v2.webnotes.in/google-authenticator/" rel="nofollow"&gt;Google Authenticator&lt;/a&gt;
 or &lt;a href="https://v2.webnotes.in/authy/" rel="nofollow"&gt;Authy&lt;/a&gt;
 so the rolling app code becomes your second login factor in place of the SMS OTP.&lt;/strong&gt; Setting it up takes about five minutes and costs nothing.&lt;/p&gt;</description></item><item><title>How to verify whether an email is genuinely from Zerodha</title><link>https://v2.webnotes.in/how-to-verify-zerodha-email/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-verify-zerodha-email/</guid><description>&lt;p&gt;An email is genuinely from Zerodha only if its sender domain is &lt;strong&gt;zerodha.com&lt;/strong&gt; or one of the ten mailer subdomains Zerodha publishes on its verify-genuine-email support page, and even a genuine email never asks for your password, OTP or PIN. The sender domain, the part of the address after the @ sign, is the one signal a fraudster cannot fake past your email provider&amp;rsquo;s authentication checks. The logo, the formatting, the tone, the client ID in the body: all of these are copied from real emails and prove nothing.&lt;/p&gt;</description></item><item><title>Kite app code vs external TOTP vs SMS OTP: which second factor to use</title><link>https://v2.webnotes.in/kite-app-code-totp-vs-sms-otp/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/kite-app-code-totp-vs-sms-otp/</guid><description>&lt;p&gt;Kite offers three ways to satisfy the second factor of a two-factor login: the in-app &lt;strong&gt;app code&lt;/strong&gt;, an external authenticator &lt;strong&gt;TOTP&lt;/strong&gt;, and &lt;strong&gt;SMS OTP&lt;/strong&gt;. An external authenticator TOTP is the most secure and most reliable of the three, because it computes codes offline, removes the SIM and the telecom network from the attack surface, and lets you log in to &lt;a href="https://v2.webnotes.in/kite-web/"&gt;Kite web&lt;/a&gt;
 without opening the &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 mobile app. The in-app app code is a solid default; SMS OTP is the weakest link and is best treated as a fallback only.&lt;/p&gt;</description></item><item><title>Kite app code: what it is and how it works as a login factor</title><link>https://v2.webnotes.in/kite-app-code/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/kite-app-code/</guid><description>&lt;p&gt;The &lt;strong&gt;Kite app code&lt;/strong&gt; is a six-digit time-based one-time password (TOTP) generated inside Zerodha&amp;rsquo;s &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 mobile app that you type into &lt;a href="https://v2.webnotes.in/kite-web/"&gt;Kite web&lt;/a&gt;
 as the second factor of a two-factor login. After you enter your user ID and password on Kite web, the app shows a code that is valid for 30 seconds; entering it completes the login. Zerodha documents this as the default second factor for clients who have the Kite mobile app and have not switched to an external authenticator.&lt;/p&gt;</description></item><item><title>Zerodha client password and credential policy</title><link>https://v2.webnotes.in/zerodha-client-password-policy/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-client-password-policy/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha&amp;rsquo;s client password and credential policy&lt;/strong&gt; sets no password in the account-opening welcome email; the client creates the password at first login, and a mandatory second factor, the Kite App Code or an external time-based one-time password (TOTP), sits on top of it under the cyber-security framework SEBI mandated in its circular of 3 December 2018, enforced across brokers from 30 September 2022. The login is therefore two factors deep by design, and the account holder, not the broker, carries the loss from any credential misuse.&lt;/p&gt;</description></item><item><title>Zerodha multiple incorrect 2FA notification</title><link>https://v2.webnotes.in/zerodha-multiple-incorrect-2fa-notification/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-multiple-incorrect-2fa-notification/</guid><description>&lt;p&gt;The &lt;strong&gt;Zerodha multiple incorrect 2FA notification&lt;/strong&gt; is an alert sent to your registered email and current device when several wrong two-factor authentication entries are made on your &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 login, and the account is blocked after 5 incorrect 2FA entries. The notification warns that the 2FA was entered incorrectly and that your password may be compromised, because whoever was entering the 2FA had already cleared the password stage to reach it. If you made the failed attempts yourself, a credential reset restores access; if you did not, the alert is telling you someone else got as far as your second factor.&lt;/p&gt;</description></item><item><title>Zerodha new device login notification</title><link>https://v2.webnotes.in/zerodha-new-device-login-notification/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-new-device-login-notification/</guid><description>&lt;p&gt;The &lt;strong&gt;Zerodha new device login notification&lt;/strong&gt; is an alert sent to your registered email and your current device the moment your correct &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 password is entered on a device Zerodha has not seen before, sent before two-factor authentication is completed. It tells you that your login credentials have been entered on a new device, so you can confirm the login was yours or act quickly if it was not. The notification keys on the device, which is what separates it from the &lt;a href="https://v2.webnotes.in/zerodha-login-different-city-alert/"&gt;login-from-a-different-city alert&lt;/a&gt;
 that keys on IP location.&lt;/p&gt;</description></item><item><title>How to reset 2FA on Zerodha</title><link>https://v2.webnotes.in/how-to-reset-2fa-zerodha/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-reset-2fa-zerodha/</guid><description>&lt;p&gt;&lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 requires two-factor authentication (2FA) for all &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 logins. The two options are:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;TOTP (Time-based One-Time Password)&lt;/strong&gt;: generated by an authenticator app on your phone (Google Authenticator, Authy, Microsoft Authenticator, or any RFC 6238-compliant app).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SMS OTP&lt;/strong&gt;: a 6-digit code sent to the mobile number registered with Zerodha.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;A 2FA reset is needed when you lose access to your authenticator app (phone replaced, app deleted, app data lost) or when the TOTP codes generated by the app no longer match the expected codes (time-sync issue).&lt;/p&gt;</description></item></channel></rss>