Extend TOTP authentication in Okta and Microsoft Entra to brokers, partners, agents, contractors, global help desks, and other distributed users—without requiring a mobile phone, SMS, voice call, authenticator app, security key, or software installation.
Credenti Extend provides a secure, browser-based virtual authenticator that gives users access to their rotating six-digit TOTP code wherever they are authorized to work.
No phone. No app to install. No authentication hardware to distribute.
Organizations have more authentication choices than ever. But deploying those authentication methods across every workforce can still create significant operational challenges.
Brokers may work from their own laptops. Partners may use devices managed by another company. Help desk personnel may be distributed around the world. Contact center agents may not be permitted to use personal phones. Contractors may only require access for a few months.
In these environments, authentication can become a device-management problem.
Organizations may need to:
Collect and maintain personal phone numbers
Depend on SMS or voice delivery
Require users to install authenticator applications
Issue corporate mobile phones
Purchase and inventory security keys
Ship authentication hardware around the world
Replace lost or damaged devices
Recover hardware when workers leave
Support software on endpoints they do not manage
Credenti Extend provides another approach.
Extend the TOTP authentication already available in Okta and Microsoft Entra without extending device-management responsibilities to every user.

Credenti Extend brings the familiar authenticator experience to the browser.
Instead of opening an authenticator application on a physical phone, users open their Credenti Extend virtual authenticator.
When a PIN is configured, the user unlocks the virtual authenticator much like they would unlock a physical phone. Extend then displays the current six-digit TOTP code.
The user enters or copies the code into the existing Okta or Microsoft Entra authentication experience.
The identity provider validates the TOTP and continues enforcing the organization's authentication and access policies.


The user opens Credenti Extend through a supported web browser.

When configured, the user enters their personal PIN to unlock their virtual authenticator.

Credenti Extend displays the user's current six-digit time-based one-time password. The code automatically rotates based on the configured TOTP interval.

The user enters the code into the normal Okta or Microsoft Entra authentication prompt.

Okta or Microsoft Entra validates the TOTP and applies the organization's existing authentication and access policies.

A virtual authenticator shouldn't require a physical phone just to activate it.
Credenti Extend provides a phone-independent enrollment experience.
From that point forward, the user can retrieve the current TOTP directly from Credenti Extend without receiving each authentication code through email.
Secondary email establishes the user during enrollment. It does not replace SMS as another mechanism for delivering every TOTP.

During first-time activation, Credenti Extend sends a six-digit verification code to the user's registered secondary email address.

The user enters the verification code to demonstrate access to that email account. The secondary email should be independent of the Okta or Microsoft Entra identity environment being protected.

Based on organizational policy, the user can establish a personal PIN to protect access to the virtual authenticator.

The user's TOTP enrollment is completed and their virtual authenticator becomes available.
Credenti Extend isn't another identity provider.
It extends an authentication method your identity infrastructure already understands.
Credenti Extend works with TOTP authentication supported by Okta. Okta continues to enforce authentication policy and validate the user's TOTP.
Credenti Extend works with OATH TOTP authentication supported by Microsoft Entra ID. Entra continues to enforce authentication policy and validate the user's TOTP.
Keep your IdP. Keep your policies. Keep TOTP. Remove the physical-device dependency.

This is one of the most important differences with Credenti Extend.
Brokers, partners, agents, contractors, outsourced personnel, and other external users frequently work from personally owned or independently managed endpoints.
The organization may not have:
Administrative rights to the endpoint
MDM control
Authority to install applications
Authority to modify browser configurations
Ownership of the user's phone
A practical way to distribute authentication hardware
Credenti Extend is browser based.
Users don't need to install an authenticator application, desktop agent, or other Credenti software simply to retrieve their TOTP.
Your organization can control application access without having to control the user's device.
Provide brokers, financial agents, advisors, and other distributed users with enterprise MFA without issuing phones or installing authentication software on independently managed devices.
Extend protected application access to partners and vendors while avoiding endpoint installation requirements on devices owned by another organization.
Authenticate distributed support personnel without procuring and shipping authentication hardware across offices, countries, and outsourced providers.
Support high-volume, shift-based, outsourced, and high-turnover agent populations without depending on personal phones.
Provide MFA to short-term users without creating a physical authentication-device lifecycle.
Support users working from personally owned endpoints without requiring corporate authentication software to be installed on those devices.
Traditional authentication hardware can create an operational process that extends far beyond authentication.
There is no physical TOTP device to ship, recover, or replace.

Credenti Extend is a browser-based virtual authenticator that allows users to access TOTP authentication codes without requiring a physical mobile phone, SMS, voice calls, authenticator application, or physical TOTP token.
Yes. Credenti Extend provides a phone-independent way for users to access TOTP authentication supported by Okta and Microsoft Entra.
No. Users access their virtual authenticator through a browser. No authenticator application, desktop agent, or browser extension needs to be installed simply to retrieve the TOTP.
Yes. Credenti Extend is designed to work with TOTP authentication supported by Okta. Okta continues to validate the TOTP and enforce the organization's authentication policies.
Yes. Credenti Extend works with OATH TOTP authentication supported by Microsoft Entra ID. Entra remains responsible for validating the authentication code and enforcing authentication policy.
Credenti Extend provides an alternative way to make TOTP available for populations where requiring a physical phone or authenticator application creates operational challenges. It does not replace the identity provider itself.
Credenti Extend can provide a phone-independent alternative for appropriate authentication workflows currently dependent on SMS or voice OTP delivery. The user's TOTP is made available through their virtual authenticator instead of being delivered through a telecommunications provider.
No phone number is required to deliver the TOTP because the user retrieves it from the virtual authenticator rather than through SMS or voice.
During first-time enrollment, Credenti Extend sends a six-digit verification code to the user's registered secondary email. After successful verification, the user can establish a personal PIN when configured and complete activation of the virtual authenticator.
The secondary email provides an independent channel for verifying the user during first-time enrollment. It should not depend on the same Okta or Microsoft Entra environment being protected.
No. Secondary email is used for identity verification during enrollment rather than to deliver every TOTP authentication code.
When configured, the PIN protects access to the virtual authenticator. The experience is similar to unlocking a physical phone with a PIN before accessing an authenticator application.
No. TOTP is not considered phishing-resistant authentication. Organizations requiring phishing-resistant authentication should use methods designed for that requirement, such as passkeys or FIDO2/WebAuthn authentication where appropriate.
Credenti Extend addresses a different problem: making TOTP operationally practical for populations where phones, authenticator applications, security keys, or endpoint installations create significant barriers.
Credenti Extend is particularly suited to brokers, financial agents, partners, contractors, global help desk personnel, BPO workers, contact center agents, temporary workers, and other extended workforce populations.
Yes. BYOD and independently managed endpoints are important Credenti Extend use cases because users can access their virtual authenticator without requiring the organization to install authentication software on the endpoint.
Your workforce doesn't end with employees carrying corporate phones and laptops. Give brokers, partners, agents, contractors, global help desks, and distributed users access to enterprise MFA without turning authentication into another device-management operation. Keep Okta or Microsoft Entra. Extend TOTP. Remove the device dependency.