Google Auth

General

In order to enable the agents to log in with Google Auth, follow the steps below:

1

Go to the settings page of your account: https://myaccount.google.com/u/1/security

Start the authenticator flow

2

MFA Onboarding

Click on the authenticator app option to configure the MFA.

3

Get secret instead of code

When seeing the QR code, select the option "Can't scan it?"

4

Copy the key

5

Store key in password manager

Now add the key for the password manager in a password manager of choice. We recommend using a password manager that easily allows for the extraction of the key like 1Password or Bitwarden

6

Fulfil the the flow and enable 2-Step Verification

7

Set up authentication in Aikido Pentest

Write your instructions in a similar format as below

Step 1: Go to domain.com/login
Step 2: Select "Google Login". You will be redirected to accounts.google.com
Step 3: provide the following credentials:
- username: [email protected]
- password: wrongpassword
Step 4: Generate the TOTP and log in
Success criteria: When successfully logged in, you will see "Hello Patrick" on the homescreen
8

Add the TOTP URL

Add the key in the correct base32 format. When adding the key from Google, make sure to remove the spaces

Last updated

Was this helpful?