here's an example of a possible php totp implementation: https://gist.github.com/jamesliu96/9de800a55e8abea42f84e208971b6579 perhaps one should implement a more robust one :) make it optional, not mandatary, additional to current user-password challenge i'll submit a pr if i have time to do so