{"id":136,"date":"2026-09-13T05:00:16","date_gmt":"2026-09-13T05:00:16","guid":{"rendered":"https:\/\/www.flowlab.works\/blog\/2026\/09\/13\/two-factor-authentication-apps\/"},"modified":"2026-09-13T05:00:20","modified_gmt":"2026-09-13T05:00:20","slug":"two-factor-authentication-apps","status":"publish","type":"post","link":"https:\/\/www.flowlab.works\/blog\/2026\/09\/13\/two-factor-authentication-apps\/","title":{"rendered":"SMEs: Exact Developer Specs for Two Factor Authentication Apps"},"content":{"rendered":"<\/p>\n<p>For most SMEs, the right move is to delegate authentication to a standards-based identity provider using OIDC or SAML rather than building 2FA from scratch. Use phishing-resistant methods like push or FIDO for admins and privileged accounts, and methods like TOTP or SMS for lower-risk customer journeys. Whichever route you choose, give your developer clear specifications: authorization code flow, PKCE for public clients, defined redirect URIs, and proper JWT verification.<\/p>\n<hr>\n<blockquote>\n<p><strong>TL;DR:<\/strong><\/p>\n<ul>\n<li>Delegating authentication to a standards-based IdP reduces long-term security and maintenance risks, especially for high-risk or regulated environments.<\/li>\n<li>FIDO\/WebAuthn and push notifications are recommended for privileged accounts and high-value transactions due to their phishing resistance.<\/li>\n<li>Clear specifications for protocol flow, endpoints, redirect URIs, and acceptance testing are essential to ensure secure and reliable implementation.<\/li>\n<li>Recovery processes must include multi-step human verification and logging to prevent social engineering attacks that bypass second-factor protections.<\/li>\n<li>Costs and ongoing maintenance, such as certificate rotation and patching, should be considered from the start, with ownership clearly defined for policies and technical updates.<\/li>\n<\/ul>\n<\/blockquote>\n<hr>\n<div data-blg-cta=\"after_tldr\" data-blg-cta-layout=\"banner\" style=\"margin:28px 0;font-family:-apple-system, BlinkMacSystemFont, &apos;Segoe UI&apos;, Roboto, Helvetica, Arial, sans-serif\">\n<div style=\"border-radius:26px;padding:min(22px,3.2vw);background:radial-gradient(circle at 100% 0%,#ffe7d1 0 150px,rgba(255,255,255,0) 151px),radial-gradient(circle at 0% 100%,#ffe7d1 0 130px,rgba(255,255,255,0) 131px),linear-gradient(180deg,#ffefe0 0%,#fff7f0 100%)\">\n<div style=\"background:#ffffff;border-radius:18px;overflow:hidden\">\n<div style=\"padding:34px 30px;text-align:center\">\n<div style=\"margin:0 0 18px\"><span style=\"display:inline-block;max-width:100%;border-radius:999px;padding:6px 13px;font-size:12px;font-weight:800;letter-spacing:0.1em;text-transform:uppercase;line-height:1.3;background:#FF7A00;color:#ffffff\">Flowlab<\/span><\/div>\n<div style=\"font-size:26px;font-weight:800;line-height:1.2;letter-spacing:-0.01em;color:#1f2937;margin:0\">Find the Right App Approach<\/div>\n<div style=\"width:56px;height:6px;border-radius:3px;background:#FF7A00;margin:12px 0 14px;margin-left:auto;margin-right:auto\"><\/div>\n<div style=\"font-size:15px;line-height:1.55;color:#64748b;margin:0 0 24px;max-width:44em;margin-left:auto;margin-right:auto\">FlowLab helps SMEs clarify operational needs and identify practical app options before development, without unnecessary technical jargon or commitment pressure.<\/div>\n<p><a href=\"https:\/\/flowlab.works\" style=\"display:inline-flex;align-items:center;gap:9px;border-radius:10px;font-weight:700;font-size:15px;text-decoration:none;padding:13px 22px 13px 26px;background:#FF7A00;color:#ffffff\">Start with an app fit review<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<h2 id=\"table-of-contents\" tabindex=\"-1\">Table of Contents<\/h2>\n<ul>\n<li><a href=\"#when-to-delegate-authentication-to-an-idp-and-when-to-build-2fa-into-your-app\">When to delegate authentication to an IdP and when to build 2FA into your app<\/a><\/li>\n<li><a href=\"#which-second-factor-methods-actually-fit-your-use-case\">Which second-factor methods actually fit your use case<\/a><\/li>\n<li><a href=\"#what-to-give-your-developer-the-integration-checklist\">What to give your developer: the integration checklist<\/a><\/li>\n<li><a href=\"#security-checklist-the-controls-that-make-2fa-actually-work\">Security checklist: the controls that make 2FA actually work<\/a><\/li>\n<li><a href=\"#costs-maintenance-and-who-owns-what-afterwards\">Costs, maintenance and who owns what afterwards<\/a><\/li>\n<li><a href=\"#how-flowlab-scopes-and-delivers-2fa-work-for-smes\">How Flowlab scopes and delivers 2FA work for SMEs<\/a><\/li>\n<li><a href=\"#get-a-complimentary-app-fit-review-before-you-brief-a-developer\">Get a complimentary app fit review before you brief a developer<\/a><\/li>\n<li><a href=\"#sources\">Sources<\/a><\/li>\n<li><a href=\"#faq\">FAQ<\/a><\/li>\n<\/ul>\n<h2 id=\"when-to-delegate-authentication-to-an-idp-and-when-to-build-2fa-into-your-app\" tabindex=\"-1\">When to delegate authentication to an IdP and when to build 2FA into your app<\/h2>\n<p>Delegating authentication means your application hands the login process to a specialist identity provider (IdP) rather than handling passwords and codes itself. The app receives a signed token confirming who the user is, and never touches the credential directly. Standard protocols such as OIDC and SAML reduce risk precisely because they\u2019ve been tested against years of real attacks. A <a href=\"https:\/\/docs-r.eiam.admin.ch\/index.php?c=intoidcqoa&amp;l=de\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">QoA parameter<\/a> can even request a minimum assurance level, so the IdP presents a stronger method automatically when the transaction warrants it.<\/p>\n<p>In-app 2FA still has a place. If you\u2019re building a small internal tool with a handful of staff and no regulatory exposure, coding a TOTP check yourself might be faster and cheaper than integrating an external IdP. The drawback is that you now own every security update, every edge case, and every future vulnerability that surfaces in your custom code.<\/p>\n<p>Decide based on:<\/p>\n<ul>\n<li><strong>Regulatory exposure<\/strong> \u2014 sectors with compliance obligations should lean towards audited, standards-based providers.<\/li>\n<li><strong>Admin access risk<\/strong> \u2014 anyone with elevated permissions needs stronger protection than a general user.<\/li>\n<li><strong>Developer resources<\/strong> \u2014 a small team with limited security experience benefits from an IdP doing the heavy lifting.<\/li>\n<li><strong>Budget for the long term<\/strong> \u2014 custom systems cost less upfront and considerably more to maintain.<\/li>\n<\/ul>\n<p>Practitioner guidance is consistent on this point: projects that build proprietary 2FA rather than relying on standard protocols tend to carry higher long-term maintenance and security risk than teams expect at the outset.<\/p>\n<h2 id=\"which-second-factor-methods-actually-fit-your-use-case\" tabindex=\"-1\">Which second-factor methods actually fit your use case<\/h2>\n<p>Not every login needs the same level of friction. Matching the method to the risk of the transaction keeps staff and customers moving without weakening protection where it matters.<\/p>\n<ol>\n<li><strong>TOTP (time-based one-time passcode)<\/strong> generates a six-digit code inside an authenticator app that refreshes every 30 seconds. It works offline, costs nothing per verification, and suits staff logins or medium-risk customer accounts well.<\/li>\n<li><strong>SMS OTP<\/strong> sends a code by text message. It\u2019s familiar to almost every user and requires no app installation, but it depends on mobile network reach and carries known interception risks, so it belongs on lower-risk flows only, never on admin or financial approval accounts.<\/li>\n<li><strong>Push notifications<\/strong> send an approval prompt to a registered device, where the user taps to confirm. This adds context (location, device, time) that a bare code can\u2019t, and it works well for staff and customer journeys with moderate risk.<\/li>\n<li><strong>FIDO\/WebAuthn hardware keys<\/strong> bind authentication to a physical device or platform credential that can\u2019t be phished, because the cryptographic check happens against the exact origin requesting it. Industry guidance consistently points to FIDO and authenticated push as more resilient to phishing than SMS OTP, which is why privileged accounts and high-value transactions should default to one of these two.<\/li>\n<\/ol>\n<p>Cost and distribution matter too. SMS carries a per-message fee at scale; hardware keys need procurement and replacement logistics; push and TOTP are effectively free once integrated. For a customer-facing app with thousands of users, that arithmetic often decides the method before security even enters the conversation.<\/p>\n<h2 id=\"what-to-give-your-developer-the-integration-checklist\" tabindex=\"-1\">What to give your developer: the integration checklist<\/h2>\n<p>A developer can only build what you specify. Vague briefs like \u201cadd two-factor authentication\u201d produce vague, expensive rework later. Hand over the following before any code is written.<\/p>\n<p><strong>Protocol and flow requirements:<\/strong><\/p>\n<ul>\n<li>Require the <strong>authorization code flow<\/strong> rather than older, less secure flows. Technical guidance on OIDC integration <a href=\"https:\/\/www.eiam.admin.ch\/r\/P\/_9840245557_eIAM_-_Integration_von_Applikationen_mit_OIDC.pdf?t=1610557429\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">recommends this pattern<\/a> specifically because it keeps tokens out of the browser\u2019s history and address bar.<\/li>\n<li>Specify whether each client is <strong>confidential or public<\/strong>, and require <strong>PKCE<\/strong> (Proof Key for Code Exchange) on any public client, such as a mobile app or single-page web app, to prevent authorization code interception.<\/li>\n<\/ul>\n<p><strong>Endpoints and token handling:<\/strong><\/p>\n<ul>\n<li>Confirm the IdP\u2019s discovery document, token endpoint, and userinfo endpoint are documented and reachable from your environment.<\/li>\n<li>Require ID token signature verification on every login, not just at initial setup. Extracts from real-world integration patterns warn specifically against misusing ID tokens for API authorisation, a common shortcut that creates security gaps later.<\/li>\n<\/ul>\n<p><strong>Redirect and session security:<\/strong><\/p>\n<ul>\n<li>List every redirect URI explicitly. Wildcards or loosely matched callback URLs are a common source of token-leak vulnerabilities.<\/li>\n<li>Define CORS rules and allowed origins before the developer starts, not after testing begins.<\/li>\n<li>Specify session length, idle timeout, and what happens to existing sessions when a password or second factor changes.<\/li>\n<\/ul>\n<p><strong>Acceptance tests to demand before sign-off:<\/strong><\/p>\n<ul>\n<li>Successful and failed authorization code exchange<\/li>\n<li>Token signature and expiry validation<\/li>\n<li>A step-up prompt triggering correctly for a sensitive action<\/li>\n<li>A simulated recovery flow, checked for account takeover risk<\/li>\n<\/ul>\n<p><strong>Pro Tip:<\/strong> <em>Ask your developer to demonstrate a failed login attempt with an expired or tampered token, not just a successful one. Most integration bugs hide in the failure paths, not the happy path.<\/em><\/p>\n<p>If your organisation needs to connect to a legacy SAML identity provider or a government-issued identity service, an identity broker (the Keycloak pattern is a common example) can convert SAML responses into JWTs your app already understands, avoiding a second, parallel authentication system.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.flowlab.works\/blog\/wp-content\/uploads\/2026\/09\/1789146397855_Identity-broker-converting-SAML-into-JWT.jpeg\" alt=\"Identity broker converting SAML into JWT\"><\/p>\n<h2 id=\"security-checklist-the-controls-that-make-2fa-actually-work\" tabindex=\"-1\">Security checklist: the controls that make 2FA actually work<\/h2>\n<p>Two-factor authentication is not a standalone fix. Government guidance on secure remote access is explicit that 2FA works best alongside strong password hygiene, regular patching, and active monitoring, not as a replacement for any of them.<\/p>\n<p>Build these controls in alongside your second factor:<\/p>\n<ul>\n<li><strong>Password policy minimums<\/strong> paired with account lockout after repeated failed attempts.<\/li>\n<li><strong>Least-privilege access<\/strong>, so a compromised standard account can\u2019t reach admin functions even if the second factor is bypassed somehow.<\/li>\n<li><strong>Anomaly and step-up rules<\/strong> that flag logins from new devices or unusual locations and request a stronger factor before allowing access.<\/li>\n<li><strong>A documented recovery process<\/strong>, including backup codes issued sparingly, a verified support workflow, and centralised logging of every recovery attempt.<\/li>\n<\/ul>\n<blockquote>\n<p><strong>The real gap most SMEs miss:<\/strong> phishing resistance isn\u2019t just about which method you choose. It\u2019s about whether your recovery process can be socially engineered around the second factor entirely. A support desk that resets 2FA on a phone call is a bigger risk than weak passwords.<\/p>\n<\/blockquote>\n<p>Recovery deserves particular care. Multi-step human verification before reissuing access, strict limits on backup-code issuance, and centralised logging of recovery attempts close off the most common route attackers use to bypass a second factor without ever cracking it.<\/p>\n<h2 id=\"costs-maintenance-and-who-owns-what-afterwards\" tabindex=\"-1\">Costs, maintenance and who owns what afterwards<\/h2>\n<p>Budget for four categories: initial development, any IdP subscription fees, per-message SMS costs if you use them, and hardware key procurement for privileged staff. Development is usually the largest one-off cost; SMS and hardware keys are the ongoing, usage-linked ones.<\/p>\n<p>Maintenance doesn\u2019t stop at launch. SMEs routinely underbudget lifecycle tasks such as certificate rotation, library updates, and dependency patching, and skipping these creates the exact vulnerabilities 2FA was meant to close. Build them into your service-level agreement upfront, not as an afterthought.<\/p>\n<p>Ownership matters too. Policy changes (who needs step-up, which roles need FIDO) typically live with whoever manages the central IdP configuration. Application-level changes (how the app requests and handles tokens) sit with your development team. Ask for:<\/p>\n<ul>\n<li>A clear maintenance line item in the initial scope<\/li>\n<li>Named ownership for certificate and key rotation<\/li>\n<li>An agreed response time for security patches<\/li>\n<\/ul>\n<h2 id=\"how-flowlab-scopes-and-delivers-2fa-work-for-smes\" tabindex=\"-1\">How Flowlab scopes and delivers 2FA work for SMEs<\/h2>\n<p>Every 2FA project starts with a question, not a solution: what is the actual operational risk you\u2019re trying to close? A complimentary app fit review works through that before any development conversation happens, weighing whether adapting an existing product foundation gets you there faster than a custom build or whether your workflow genuinely needs something bespoke.<\/p>\n<p>The pitfalls repeat across SME projects. Maintenance budgets get set for the launch date and nothing after. Recovery flows get built as an afterthought, then become the weakest link in the whole system. And SMS gets used for admin accounts because it was the fastest thing to wire up, not because anyone weighed the risk.<\/p>\n<p>None of this is exotic. It\u2019s what happens when authentication gets treated as a checkbox instead of a design decision made against your actual risk profile.<\/p>\n<blockquote>\n<p><em>\u2014 Ronald<\/em><\/p>\n<\/blockquote>\n<h2 id=\"get-a-complimentary-app-fit-review-before-you-brief-a-developer\" tabindex=\"-1\">Get a complimentary app fit review before you brief a developer<\/h2>\n<p>This company offers a practical route for SMEs who\u2019d rather confirm the right approach before spending on development than discover it was wrong halfway through a build. A <a href=\"https:\/\/www.flowlab.works\/app-development-singapore\" target=\"_blank\" rel=\"noopener\">complimentary app fit review<\/a> looks at your actual workflow and tells you plainly whether a delegated IdP integration, an adapted existing product, or a genuinely custom build fits your situation, along with a realistic cost range and timeline before anything is committed.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.flowlab.works\/blog\/wp-content\/uploads\/2026\/08\/1787190647142_flowlab.jpg\" alt=\"Flowlab\"><\/p>\n<p>That review exists specifically to stop SMEs overspending on complexity they don\u2019t need, or underbuilding something that creates risk later. If you\u2019re weighing up costs before you commit to a scope, the <a href=\"https:\/\/www.flowlab.works\/app-development-cost-singapore\" target=\"_blank\" rel=\"noopener\">app development cost guide<\/a> gives a useful sense of what different approaches typically involve. When you\u2019re ready to talk specifics, book a review and get a clear answer on the right path for your app.<\/p>\n<h2 id=\"sources\" tabindex=\"-1\">Sources<\/h2>\n<p>Technical guidance cited throughout this piece comes from documented OIDC integration patterns and <a href=\"https:\/\/www.agov.admin.ch\/de\/agov-in-cloud-saas-hyperscaler-architekturen\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">national identity service architectures<\/a>. For broader website security context, see this SMB security checklist, and for ongoing authentication auditing, <a href=\"https:\/\/aisyndicate.io\/\" target=\"_blank\" rel=\"noopener\">Aisyndicate<\/a>.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.eiam.admin.ch\/r\/P\/_9840245557_eIAM_-_Integration_von_Applikationen_mit_OIDC.pdf?t=1610557429\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Integration von OpenID Connect<\/a><\/li>\n<li><a href=\"https:\/\/docs-r.eiam.admin.ch\/index.php?c=intoidcqoa&amp;l=de\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">OIDC QoA Spezifikation<\/a><\/li>\n<\/ul>\n<h2 id=\"faq\" tabindex=\"-1\">FAQ<\/h2>\n<h3 id=\"should-i-use-oidc-or-saml-for-my-application\" tabindex=\"-1\">Should I use OIDC or SAML for my application?<\/h3>\n<p>OIDC is generally simpler to integrate with modern web and mobile apps, while SAML remains common with legacy enterprise and government identity services; an identity broker can bridge the two if you need both.<\/p>\n<h3 id=\"whats-the-difference-between-delegated-idp-and-in-app-two-factor-authentication-apps\" tabindex=\"-1\">What\u2019s the difference between delegated IdP and in-app two factor authentication apps?<\/h3>\n<p>Delegated IdP hands authentication to an external, standards-based provider, while in-app 2FA means your own codebase generates and checks the second factor, carrying more long-term maintenance risk.<\/p>\n<h3 id=\"is-sms-otp-secure-enough-for-customer-accounts\" tabindex=\"-1\">Is SMS OTP secure enough for customer accounts?<\/h3>\n<p>SMS OTP is acceptable for lower-risk customer journeys but should never be the only option for admin or privileged accounts, where phishing-resistant methods like FIDO or push are the stronger choice.<\/p>\n<h3 id=\"how-much-does-adding-2fa-to-an-existing-app-typically-cost\" tabindex=\"-1\">How much does adding 2FA to an existing app typically cost?<\/h3>\n<p>Costs vary by integration complexity, chosen methods, and whether you\u2019re adapting an existing product or building custom; Flowlab\u2019s complimentary app fit review gives a scoped estimate before you commit to development.<\/p>\n<h3 id=\"what-should-a-developers-acceptance-tests-for-2fa-include\" tabindex=\"-1\">What should a developer\u2019s acceptance tests for 2FA include?<\/h3>\n<p>At minimum, tests should cover successful and failed authorization code exchange, token signature verification, a working step-up prompt, and a simulated recovery flow check.<\/p>\n<h2 id=\"recommended\" tabindex=\"-1\">Recommended<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.flowlab.works\/app-development-singapore\" target=\"_blank\" rel=\"noopener\">App Developer Singapore for SMEs<\/a><\/li>\n<li><a href=\"https:\/\/www.flowlab.works\/how-to-choose-app-developer-singapore\" target=\"_blank\" rel=\"noopener\">How to Choose an App Developer in Singapore<\/a><\/li>\n<li><a href=\"https:\/\/www.flowlab.works\/app-development-cost-singapore\" target=\"_blank\" rel=\"noopener\">App Development Cost Singapore | SME Pricing Guide<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Commission two factor authentication apps with exact specs, security and upkeep checklists for SMEs, and book a free app fit review.<\/p>\n","protected":false},"author":1,"featured_media":137,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/posts\/136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/comments?post=136"}],"version-history":[{"count":1,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/posts\/136\/revisions"}],"predecessor-version":[{"id":139,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/posts\/136\/revisions\/139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/media\/137"}],"wp:attachment":[{"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/media?parent=136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/categories?post=136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.flowlab.works\/blog\/wp-json\/wp\/v2\/tags?post=136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}