Requesting factory-set seeds for Token2 hardware tokens

Last updated 29 Jul 2026

Every standalone TOTP token ships pre-seeded. After your order arrives, you can download those factory-set seeds yourself, in the format your system needs — no ticket, no waiting. Seed downloads are handled entirely from your Token2 account: you confirm your identity by email, choose a format, and download immediately. There is no separate support request to raise.

What does it cost?

Nothing. There is no fee and no licence charge for requesting your seeds, in any format.

Which devices can I request seeds for?

Any standalone TOTP token — classic and programmable — comes pre-seeded, and the download works the same way for both. On programmable tokens the factory seed is used for quality checks and left in place, so the process is identical.

Two limits are worth knowing:

  • Reprogrammed tokens: there is no “factory reset” for seeds. If a programmable token has been reprogrammed or reconfigured, the original factory seed can no longer be used.
  • Security keys: FIDO2 / security keys with OTP functionality ship with empty seeds — you generate your own with our tools. There is no factory-seed download for security keys.

⚠ Request seeds only after delivery. Downloading your seeds confirms that the physical products have been delivered successfully. Please don’t request them before the tokens arrive: doing so can affect your ability to have a damaged or undelivered order resent or refunded.

How to download your seeds

  1. Sign in to your Token2 account using the email address associated with your order. Orders you placed as a guest with that same email — and any orders delegated to you — appear automatically once you’re signed in.
  2. Open the seed download page in your account. Your eligible orders are listed there, each showing its order number, date, and token count.
  3. Confirm your identity by email. For your protection, each download requires a one-time email confirmation. We send a code to your account email; enter it to unlock the download for a short time.
  4. Select the order(s) you want seeds for, or use Select all. Nothing is pre-selected.
  5. Choose your format(s) for your system (see the list below).
  6. Choose how it’s protected — an encryption method: PGP or a password-protected zip (details below).
  7. Download. Your seed file is generated and downloaded straight away. A confirmation is also emailed to you for your records.

Authorised users only. Seeds can be downloaded only by people authorised for the order. The person who placed the order is always authorised, and they can grant access to additional email addresses — see Delegating access for requesting seeds.

Choosing a format

Select whichever your authentication system expects. Available formats include:

  • Base32 and Hex — the raw secret, for manual entry or custom tooling.
  • Microsoft Entra ID / Azure MFA (CSV) — for Microsoft’s hardware-token import.
  • Microsoft Graph API (JSON).
  • PSKC (XML) — the OATH standard interchange format.
  • HelloID, Idaptive / CyberArk, multiOTP, privacyIDEA, and WatchGuard AuthPoint — system-specific exports.

Using Microsoft Entra ID / Azure MFA: choose the CSV for Azure MFA format. To import it, follow our Entra ID hardware-token guide. Note that importing hardware OATH tokens requires a Microsoft Entra ID Premium P1 or P2 licence.

Choosing how your seeds are protected

Your seeds are the secret keys to your tokens, so the download is always protected. Pick the method you’re comfortable with:

  • Encrypt to your PGP key (recommended). If you use PGP/GPG, paste your public key and we encrypt the file so only you can open it. This is the strongest option. Make sure your key block includes both the -----BEGIN PGP PUBLIC KEY BLOCK----- and -----END PGP PUBLIC KEY BLOCK----- lines.
  • Password-protected zip — AES-256. If you’re not using PGP, choose a strong password and we’ll produce an AES-256 encrypted zip. Use letters and digits for the password. This encryption is strong, but Windows Explorer can’t open it directly — use the free 7-Zip or PeaZip to extract it.

Advanced options: a Windows-compatible zip (weaker encryption) and an unencrypted plaintext option are available under Advanced options. Plaintext leaves your seeds unprotected on your device — only use it on a trusted, offline machine.

Oracle Identity Cloud Service (IDCS) orders

If your order is tied to an Oracle Identity Cloud Service (IDCS) deployment, seeds are delivered in a single secure way: encrypted directly to your own IDCS instance. When any Oracle order is selected, the standard formats and other encryption options don’t apply — the download is Oracle-encrypted only.

You provide just your IDCS domain — enter only the first part, for example idcs-a1b2c3; the rest (.identity.oraclecloud.com) is fixed for you. You enter it once and it applies to every Oracle order in the download. Each seed is encrypted to your IDCS instance’s public key, which is fetched live from your instance at download time. Nothing is decrypted on our side — only your IDCS instance can open the result.

Why the file looks different each time: Oracle encryption deliberately produces different-looking output every time, even for the same token. That’s a security feature, not an error — your IDCS instance will read it correctly.

Frequently asked questions

How do I decrypt the PGP file?
Use your usual PGP/GPG software with your private key. We’re not able to provide support for PGP tools themselves — if you’re not comfortable with PGP, use the password-protected zip method instead.

My PGP file is empty / won’t decrypt.
This usually means the public key pasted into the form was incomplete or corrupted. Check that both the BEGIN and END PGP PUBLIC KEY BLOCK lines are present, and request again.

I can’t open the encrypted zip.
The AES-256 zip won’t open in Windows Explorer — that’s expected. Use the free 7-Zip or PeaZip. If the password was rejected, avoid symbols such as slashes, quotes, and backticks; letters and digits work reliably (use a longer password to keep it strong).

The CSV downloaded as a .txt file. Is that a problem?
No. A .txt extension keeps the file from auto-opening in Excel, which can silently break the format. Edit it only in a plain-text editor such as Notepad. Microsoft Entra ID accepts the .txt file as-is.

I don’t see my order.
Make sure you’re signed in with the exact email used on the order. If it was placed by someone else, ask them to delegate access to your email address (see the delegation guide). If you purchased through a reseller, contact them for your order details. Still stuck? Contact us.

Seed request procedures