Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

648 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Two-Factor TOTP

License ownCloud OSPO Docker Hub

Two-Factor TOTP adds Time-based One-Time Password (TOTP) second-factor authentication to ownCloud Server. It is compatible with standard TOTP authenticator apps including Google Authenticator, Twilio Authy and the open-source OTP Authenticator from F-Droid, allowing users to secure their ownCloud accounts with a time-based code from their mobile device.

Part of Classic (OC10)

This app is part of the ownCloud Server (OC10) two-factor authentication ecosystem, providing TOTP-based second-factor login.

The ownCloud Server is available on Docker Hub.

Getting Started

Follow the steps below to install and enable TOTP-based two-factor authentication.

Installation

Install from the ownCloud Marketplace, or manually:

cd apps
git clone https://github.com/owncloud/twofactor_totp.git
cd ..
php occ app:enable twofactor_totp

Enabling TOTP

Users enable TOTP in their personal settings by scanning the QR code displayed in the settings page with their authenticator app.

Running Tests

make test                  # Run all tests (PHP unit + JS if present)
phpunit -c phpunit.xml     # Run PHP unit tests directly
phpunit -c phpunit.integration.xml  # Run integration tests

Documentation

Community & Support

Star this repo and Watch for release notifications!

Contributing

We welcome contributions! Please read the Contributing Guidelines and our Code of Conduct before getting started.

Workflow

  • Rebase Early, Rebase Often! We use a rebase workflow. Always rebase on the target branch before submitting a PR.
  • Dependabot: Automated dependency updates are managed via Dependabot. Review and merge dependency PRs promptly.
  • Signed Commits: All commits must be PGP/GPG signed. See GitHub's signing guide.
  • DCO Sign-off: Every commit must carry a Signed-off-by line:
    git commit -s -S -m "your commit message"
    
  • GitHub Actions Policy: Workflows may only use actions that are (a) owned by owncloud, (b) created by GitHub (actions/*), or (c) verified in the GitHub Marketplace.

Translations

Help translate this project on Transifex: https://explore.transifex.com/owncloud-org/owncloud/

Please submit translations via Transifex -- do not open pull requests for translation changes.

Security

Do not open a public GitHub issue for security vulnerabilities.

Report vulnerabilities at https://security.owncloud.com -- see SECURITY.md.

Bug bounty: YesWeHack ownCloud Program

License

This project is licensed under the AGPL-3.0.

About the ownCloud OSPO

The Kiteworks Open Source Program Office, operating under the ownCloud brand, launched on May 5, 2026, to steward the open source ecosystem around ownCloud's products. The OSPO ensures transparent governance, license compliance, community health, and sustainable collaboration between the open source community and Kiteworks, which acquired ownCloud in 2023.

For questions about the OSPO or licensing, contact ospo@kiteworks.com.

License Migration to Apache 2.0

The OSPO is driving a strategic relicensing of ownCloud repositories toward the Apache License 2.0, following the Apache Software Foundation's third-party license policy.

Individual repositories will migrate as their audit is completed. The LICENSE file in each repo reflects its current license status (not the target).

Current license: AGPL-3.0 (Category X per Apache policy -- cannot be included in Apache-2.0 works).

Migration prerequisites for this repository:

  • CLA/DCO coverage: All past contributors must have signed agreements permitting relicensing
  • Copyleft dependency audit: All AGPL/GPL dependencies must be replaced or isolated
  • KDE heritage review: Any code with KDE-era copyrights requires legal analysis
  • Complete relicensing: AGPL-3.0 is a strong copyleft license; migration requires full relicensing of all files, not just a header change

About

πŸ”‘ Second factor TOTP (Google Authenticator) provider for ownCloud

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors

Languages