# Define custom 2fa secret

**URL:** <https://forum.keycloak.org/t/define-custom-2fa-secret/9059>\
**Category:** Getting advice\
**Tags:** admin-rest, authentication\
**Created:** [May 13, 2021, 2:29pm UTC](https://forum.keycloak.org/t/define-custom-2fa-secret/9059 "2021-05-13T14:29:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sabana](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@sabana](https://forum.keycloak.org/u/sabana)\
**Post date:** [May 13, 2021, 2:29pm UTC](https://forum.keycloak.org/t/define-custom-2fa-secret/9059/1 "2021-05-13T14:29:13Z")

</div>

We are trying to integrate our application with keycloak. Some of our users are already using 2fa in our system, so the 2fa secrets are stored in our DB. My question is about if there’s any way to migrate these 2fa secrets along with users to keycloak?

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [May 13, 2021, 4:10pm UTC](https://forum.keycloak.org/t/define-custom-2fa-secret/9059/2 "2021-05-13T16:10:49Z")

</div>

In the Server Developer Guide, there is an example of how to build a “secret question” Authenticator, which will extend the login process and add a credential type. It is very similar to your need. You could probably modify the extension to do what you need, and then import your “2fa secrets” directly to the credential table in the db.

[https://www.keycloak.org/docs/latest/server\_development/#\_auth\_spi\_walkthrough](https://www.keycloak.org/docs/latest/server_development/#_auth_spi_walkthrough)

> <https://github.com/keycloak/keycloak/tree/main/examples/providers/authenticator>
>
> //github.com/keycloak/keycloak/tree/main/examples/providers/authenticator
