# Testing one-time codes and 2FA in Playwright

> A Playwright test that receives the code sent by email, and computes the one an authenticator app would show. Both halves of a 2FA journey.
> https://facteur.eu/en/playwright-otp-testing

## The code arrives by mail, or it is computed

A two-factor journey blocks a test suite in two places: the code sent by email, which the test cannot read, and the one from an authenticator app, which it cannot generate. Both are solvable, and not in the same way.

## The code that arrives by email

Same mechanics as a sign-up: the request goes out before the click and answers when the message lands.

### A criterion that aims at the code, not at the text

Asking for "the message carrying a code" avoids landing on an email that quotes an older code in its history.

### The code lives in its own field

Six digits, extracted on reception. Your test compares a value; it does not search HTML for a pattern.

## The code from an authenticator app

Nobody can send you that one: it is computed from the secret your enrolment screen shows. Twenty lines of Node, no dependency, and the phone stays in the drawer.

## What it changes for a suite

## The application that sends the code

The two tests above need an application that emails a code, and another that shows a shared secret on screen. La Belle Etoile does both, open to anyone: its sign-up mails a six-digit code to your test mailbox address, and its two-factor screen shows the secret the second test turns into digits. No account to create, and it only ever mails a Facteur address, which is what stops it being a relay for anyone else.

## The Playwright plugin, if you want it

It installs in one line: npm i -D playwright-facteur. The test above expects nothing from it, calls the API directly, and keeps working as it stands.
