# Is there a way for a standard user to do an OTP reset?

**URL:** <https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537>\
**Category:** Getting advice\
**Tags:** authentication\
**Created:** [March 4, 2020, 2:30pm UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537 "2020-03-04T14:30:19Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![octavian](https://avatars.discourse-cdn.com/v4/letter/o/54ee81/32.png) [@octavian](https://forum.keycloak.org/u/octavian)\
**Post date:** [March 4, 2020, 2:30pm UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/1 "2020-03-04T14:30:19Z")

</div>

I’m using Keycloak 8.0.1 at my workplace and get a lot of requests to reset the OTP codes for my users.  
The only known way for me to do this is to:

- log into keycloak with an admin account
- go to the desired realm
- go to Users / search for the user and go to their details page
- go to Credentials tab and choose Configure OTP under Reset Actions
- Send email

![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/1X/e3599a4e767fa1ce2f7b37a7ba153f2fffd9c376.png)

Is there a way for a standard user to reset his or her own OTP? It would be nice for users to have a Reset Credentials button where they could reset their password or OTP codes themselves (via email validation).

---

<div class="post-metadata">

**Author:** ![jangaraj](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jangaraj/32/5175_2.png) [@jangaraj](https://forum.keycloak.org/u/jangaraj)\
**Post date:** [March 4, 2020, 2:53pm UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/2 "2020-03-04T14:53:08Z")

</div>

User can visit own account management, where is option to delete configured authenticator - `/auth/realms/<realm>/account/totp`. User will be requested to configure new authenticator during next login. Of course this one will be not working if user doesn’t know his current authenticator code.

OTP reset via email doesn’t look good. If attacker has user credentials, then he has very likely also access to user email, so he will be able to reinitialize OTP authenticator easily. Keep in mind security, not just user experience.

IMHO the best approach is to have own “selfservice”, where you will verify user identity properly (user credentials + some additional identity factor) + user TOTP reset via Keycloak REST API.

---

<div class="post-metadata">

**Author:** ![octavian](https://avatars.discourse-cdn.com/v4/letter/o/54ee81/32.png) [@octavian](https://forum.keycloak.org/u/octavian)\
**Post date:** [March 5, 2020, 12:45pm UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/3 "2020-03-05T12:45:29Z")

</div>

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![jol002](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jol002/32/2418_2.png) [@jol002](https://forum.keycloak.org/u/jol002)\
**Post date:** [January 11, 2023, 1:42pm UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/4 "2023-01-11T13:42:13Z")

</div>

Hi Jangarai,  
I’m trying the `/auth/realms/<realm>/account/totp`, but at one of our Keycloak-instances we get the message ‘Page not found’, and at the other (test) instance we get the message ‘No access’ with a link: ‘\<\< Back to application’.  
Is there something I need to configure?

Please help me oput.  
Kind regards,  
Albert Jol

---

<div class="post-metadata">

**Author:** ![adg92](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/adg92/32/9291_2.png) [@adg92](https://forum.keycloak.org/u/adg92)\
**Post date:** [November 16, 2023, 3:37pm UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/5 "2023-11-16T15:37:17Z")

</div>

Have you ever figured it out?

---

<div class="post-metadata">

**Author:** ![Nandika](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/nandika/32/3113_2.png) [@Nandika](https://forum.keycloak.org/u/Nandika)\
**Post date:** [January 8, 2024, 9:37am UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/6 "2024-01-08T09:37:24Z")

</div>

Hi,

Did you resolve this issue?

In my use-case, I use the /auth/realms//account/totp to register MFA and after the MFA registration, I used the same link to display the list of registered MFA entries. It works in Keycloak v18. But MFA device list page does not work in version 21. Getting ‘Page not found’

Any idea?

Regards,  
Nandika

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [January 8, 2024, 11:13am UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/7 "2024-01-08T11:13:22Z")

</div>

Have you configured the `http-relative-path` option to use `/auth`?  
If not, try to use the mentione URL without `/auth` part.

---

<div class="post-metadata">

**Author:** ![Nandika](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/nandika/32/3113_2.png) [@Nandika](https://forum.keycloak.org/u/Nandika)\
**Post date:** [January 8, 2024, 11:43am UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/8 "2024-01-08T11:43:24Z")

</div>

Yes Niko,

This is my request

https://\<\>/auth/realms/\<\>/account/totp?kc\_locale=de&customer=\<\>

BR  
Nandika

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [January 8, 2024, 11:52am UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/9 "2024-01-08T11:52:52Z")

</div>

Ah, now I see… you are using the old, legacy account console, which is for long time already deprecated and was finally removed some time ago.

In the current account console, you can access your signing-in credentials with `https://{hostname}/auth/realms/{realmname}/account/#/security/signingin`

---

<div class="post-metadata">

**Author:** ![Nandika](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/nandika/32/3113_2.png) [@Nandika](https://forum.keycloak.org/u/Nandika)\
**Post date:** [January 18, 2024, 9:47am UTC](https://forum.keycloak.org/t/is-there-a-way-for-a-standard-user-to-do-an-otp-reset/1537/10 "2024-01-18T09:47:26Z")

</div>

Hi @dasniko,

Thanks for the suggestion, I’m still having the same issue. However, seems some adjustments need to be made on the application side as well. I will update the channel with the status once all done.

-Nandika
