Zerodha google authenticator – zerodha google authenticator.How to set-up Zerodha time-based one-time password-TOTP for higher security?

Looking for:

Zerodha google authenticator – zerodha google authenticator

Click here to Download

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

The only reason I even brought up the fact that Kite Connect isn’t a data vending product is because you talked about data collection. Changes can’t be based on that.

Matti And for data as add on you charge another Just give me one reason why shouldn’t we store tick data in our personal database. Are we not supposed to be smart enough?

While we understand the inconvenience, this is decision is based on updated risk and cyber security assessments. As we have already mentioned above, 2FA is mandated by SEBI for all platforms that most platforms don’t offer it is a different matter. This very likely will happen industrywide soon too. Can you please respond to this? Let SEBI say the same.

Let SEBI elaborate the definition in more correct way. Why you guys are in so much hurry. And for data as add on you charge another I am not saying any of that. I simply said policy decisions cannot be based on these considerations. This is a security policy and has nothing to do with data.

Unfortunately, the token flush times are timed to follow a large number of end of the day processes and cannot be moved. While i am a loyal user of zerodha API because of its stability, now some of the below mentioned reasons dragging me away for alternatives: 1. No OTM options buy 2. Charging per month, even when i m generating lakhs of brokerage for them.

Additional overhead in token generation because of TOTP. I understand that sooner or later it will be made mandatory, but let that time come, it could be 1 or 2 years, atleast our life will be easy till then. Why necessary trouble us when our returns are already impacted heavily because of margin rules. Can you please respond on that and provide us the reason behind this urgent need. Matti Please make it optional. Whoever wants additional security can opt for that.

The change is that we’re mandating it now, and perhaps soon for all other platforms as well. If time permits I will write a post on how to do it, but as all of us are devs here, just check below pointers.

QR holds a key you can copy that by clicking link below it. Use that key and system time to generate TOTP. Just supply the key you got from step 2. So its not so difficult to automate login. Thanks amit0. I am talking about before 1st October. May be helpful for python developers It only changes whenever you change your 2FA app or re-register. I did see your comment that a lot of things happen before you can flush it I’m assuming including calculating funds in the account.

However, I assume the token is only accessible by the user and not by Zerodha – so flushing really shouldn’t have an impact on your systems. Maybe internally you can hash the previous token and continue your processes, but flush the user token so we can generate a new one earlier?

In short I’m proposing a new internal token you use for whatever processes you have which require it I don’t know why it should be used – but whatever the reasons it solves your purpose and the user token can be flushed. Can you please share the steps in kite connect for this. What is the secret key here? What need to passed under KiteInstance. AccessToken; KiteInstance. Matti Its strange to see that these rules don’t apply to kite mobile app?

Care to explain the rationale? I understand that order placement will be rejected b. But please confirm that other read-only api’s like ltp, quote will still work. Just a question out of curiosity. The use of TOTP to safeguard against suspicious trades was a helpful feature. With this change there is no protection against such trades. Developers will always find a way around it one way already discussed here. Trying to stop them from fully automating stuff is everyone’s waste of time and resources.

Otherwise It will be difficult to find the right code for this. I understand that order placement will be rejected Yes, all order placement-related calls will be throwing Yes, this will work as before. Yes, we will update the login flow documentation , before going live i.

I would like to see the documentation updated for. Net API client. Zerodha should first update the documentation then announcement should be made. Please postpone the date.

Provide some time to user to update the code. Functionally, the APIs remain unchanged. Thanks Matti. Sorry for the confusion. I am able to login without any code changes after enabled TOTP option in kite web.

Guhan September I am using it and it is working perfectly well using selenium. Trust me it’s as seamless as without, with the added peace of having another layer of security.

I have the Authy app on 2 devices for token generation, just in case. Congrats to Zerodha team for implementing this well. JeetKumar October Hi, Consider this please. I am an “almost blind” person, and I got my API system developed because I was having major problems using kite apps and website to place order. Its an issue with every broker in India. The apps and websites are difficult to use by blind or almost blind people. Everything was ok with API, I could trade using my own “simpler” platform, built specifically for me.

Everything works with my screen reader on my simpler platform, no problems. Now you are implementing this 2FA system, which requires me to use a third party app on smart phones to get a code daily, and use that code to login within 30 seconds. Is that right? It will take me over a minute to even open the app, let alone read the code using accessibility technology of the phone By that time, the login flow has expired, am I right?

So I need to find someone everyday who can help me login to zerodha, “daily” Why is India so inconsiderate and insensitive towards blind people? SEBI has no idea that even blind people are trading? I am sincerely asking and requesting, please keep this optional.

Please do not make it manditory. Anyone who requires higher security, they can opt for the system, or else, let the user be responsible for their API and account security. You can update your terms of use and make us accept the terms, and let the user be responsible for the security.

No need for you to take the responsibility and implement password layer over layer over layer over layer in the name of security. I will happily take the responsibility of securing my API and account, no problem. Can you please give me a direct line of communication with SEBI?

I will take up this issue with them as well. If I give you a written complaint as zerodha user, can you forward it to SEBI, asking them to consider? It will have more impact on SEBI if the request goes through you, instead of me as individual Its really sad to see how insensitive decision makers are in India, specially when it comes to accessibility ZERO idea of our problems.

Totally zero. Again, sincerely asking, please please reconsider this decision. It will make things a lot lot difficult for people like me. Please reconsider this. Honest, it will make so much problem for people like me You have no idea Can someone be kind enough to give me details on how to setup this “google authenticator” app on my android phone, and then how to connect it to zerodha It appears you need to install some sort of app to login, either on mobile or PC.

Gotta find a solution for this now. Right now I use google Authenticator for one of my accounts. Can I add multiple accounts over here??

Also, you can export codes to other devices if required. They will all show the same totp. Ah then problem solved. Just had one doubt. Organise via Labels With the inbuilt labels, you can easily group and manage a large number of accounts.

The inbuilt search feature helps to find any account in seconds. You can export your data from one platform, and simply import it on the other.

Multi-device usage This 2FA app empowers you to create both cloud backups via Cloud Sync and offline backups. This is highly useful in cases where you use 2 devices or need to switch your phone. If some service does not work for you, please contact our support. Multiple language support Experience the app in a more intuitive way by using it in your language. The app comes with the support of 7 popular supported languages.

Don’t see your language in the app? Reach out. Multiple widgets With TOTP Authenticator, you can easily add multiple widgets for your favourite accounts on the home screen for quick access. These widgets come in multiple layouts, so you can choose whichever suits you the best. Personalization The app allows you to set unique icons to your accounts, either by selecting icons from the provided list or by uploading them.

This helps you to easily recognize and sort your accounts. Biometric security Protect your accounts by using biometrics Fingerprint, face scan or a 4-digit PIN. This helps protect your codes from prying eyes or in case someone gets access to your phone. You can also block screen capture via screenshots and other methods. For any questions or suggestions, reach us at info binaryboot. Developers can show information here about how their app collects and uses your data.

Learn more about data safety No information available.

 
 

 

Zerodha google authenticator – zerodha google authenticator

 
If access to the authenticator app is lost, follow these steps: Click on Forgot user ID or password? Enter User ID, PAN and select E-mail¹ or SMS. Here is how you can set up Google Authenticator or other time-based apps for Kite two-factor authentication (2FA) using your mobile.

 
 

Zerodha google authenticator – zerodha google authenticator. AutoTrader Web

 
 
This would generate a loss on the compromised account. Demat account holders are required to enable two-factor authentication by September 30, or they may end up facing difficulties in logging in to their trading accounts. Physically disabled, PWD people like me must also be considered when making “major decisions” like these.

Leave a Reply

Your email address will not be published. Required fields are marked *