# How TeslaMate Handles MFA and CAPTCHA in Its Authentication Flow

> Learn how TeslaMate handles MFA and CAPTCHA by delegating to Tesla's official endpoint. Discover efficient OAuth token management for seamless authentication.

- Repository: [TeslaMate/teslamate](https://github.com/teslamate-org/teslamate)
- Tags: internals
- Published: 2026-06-16

---

**TeslaMate delegates MFA and CAPTCHA challenges entirely to Tesla's official authentication endpoint, managing only the resulting OAuth tokens that users obtain through external login flows.**

TeslaMate is an open-source data logger for Tesla vehicles that interacts with the Tesla API. Unlike applications that implement custom authentication layers, TeslaMate's authentication flow relies entirely on externally obtained OAuth tokens, bypassing the need to handle sensitive MFA challenges or CAPTCHA verification internally.

## External OAuth Token Collection

TeslaMate does not present its own login form for credentials. Instead, the `SigninLive` module in [`lib/teslamate_web/live/signin_live/index.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/teslamate_web/live/signin_live/index.ex) prompts users to provide an access token and refresh token pair obtained by authenticating directly with Tesla's official service at `https://auth.tesla.com`.

The live view initializes with a changeset for token validation:

```elixir

# lib/teslamate_web/live/signin_live/index.ex – UI collects tokens

def mount(_params, _session, socket) do
  %{
    api: get_api(socket),
    page_title: gettext("Sign in"),
    changeset: Auth.change_tokens(),
    provider: System.get_env("TESLA_AUTH_HOST", "https://auth.tesla.com")
  }
  |> then(&{:ok, assign(socket, &1)})
end

```

This design means any MFA prompts (SMS codes, authenticator apps) or CAPTCHA challenges occur entirely on Tesla's servers. TeslaMate never processes username/password combinations or displays CAPTCHA widgets.

## Token Storage and Validation

Once submitted, the tokens pass through the `TeslaMate.Auth` context located in [`lib/teslamate/auth.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/teslamate/auth.ex). The `save/1` function validates and persists the token pair using the `TeslaMate.Auth.Tokens` schema defined in [`lib/teslamate/auth/tokens.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/teslamate/auth/tokens.ex).

```elixir

# lib/teslamate/auth.ex – saving tokens

def save(%{token: access, refresh_token: refresh}) do
  attrs = %{access: access, refresh: refresh}
  case get_tokens() do
    nil   -> create_tokens(attrs)
    token -> update_tokens(token, attrs)
  end
end

```

The system stores both the **access token** for API requests and the **refresh token** for maintaining long-term access.

## Automatic Token Refresh and Expiration Handling

TeslaMate automatically refreshes access tokens before they expire using `TeslaApi.Auth.refresh/1` in [`lib/tesla_api/auth.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/tesla_api/auth.ex). This function exchanges the stored refresh token for a new access token through Tesla's `/oauth2/v1/token` endpoint.

When a refresh fails—typically because the user must re-authenticate due to an expired MFA session or revoked credentials—the application handles the `401 Unauthorized` response by clearing stored tokens and returning to the sign-in prompt.

```elixir

# lib/tesla_api/auth.ex – token refresh (handles 401)

def refresh(%Auth{} = auth) do
  # Calls Tesla's /oauth2/v1/token endpoint with the stored refresh token.

  # On success returns a new %Auth{}; on failure the caller treats it as

  # an unauthorized state and clears stored tokens.

end

```

The `TeslaMate.Auth.delete_tokens/0` function removes invalid credentials from the database, forcing the user to obtain fresh tokens through Tesla's authentication flow again.

## Security Architecture Benefits

By delegating MFA and CAPTCHA handling to Tesla's official infrastructure, TeslaMate avoids several security risks:

- **No credential storage**: Usernames and passwords never pass through TeslaMate's servers
- **No challenge logic**: The application doesn't implement CAPTCHA solving or MFA verification algorithms
- **Upstream compliance**: Automatically inherits Tesla's security updates and authentication requirements

This architecture ensures that sensitive authentication challenges remain within Tesla's controlled environment while TeslaMate focuses exclusively on API data logging.

## Summary

- TeslaMate does not implement MFA or CAPTCHA checks internally
- Users must obtain OAuth tokens externally from `https://auth.tesla.com`, completing any required MFA or CAPTCHA challenges there
- The `SigninLive` view in [`lib/teslamate_web/live/signin_live/index.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/teslamate_web/live/signin_live/index.ex) collects only the resulting access and refresh tokens
- `TeslaMate.Auth` validates and stores tokens via [`lib/teslamate/auth.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/teslamate/auth.ex) and [`lib/teslamate/auth/tokens.ex`](https://github.com/teslamate-org/teslamate/blob/main/lib/teslamate/auth/tokens.ex)
- Automatic token refresh occurs through `TeslaApi.Auth.refresh/1`, with failures triggering token deletion via `delete_tokens/0`
- Invalid tokens result in `401 Unauthorized` responses, prompting users to re-authenticate through Tesla's official flow

## Frequently Asked Questions

### Does TeslaMate support automatic MFA code entry?

No. TeslaMate does not interact with the MFA process at all. Users must complete any multi-factor authentication steps directly on Tesla's official authentication website before copying the resulting OAuth tokens into TeslaMate.

### What happens when my Tesla account requires CAPTCHA verification?

CAPTCHA challenges are handled entirely by Tesla's authentication servers. Since TeslaMate only accepts tokens that you obtain externally, you will complete any CAPTCHA requirements during the token generation process on Tesla's site, not within the TeslaMate interface.

### Why does TeslaMate ask for tokens instead of my Tesla username and password?

TeslaMate uses an OAuth-based authentication flow that requires access and refresh tokens. This approach enhances security by ensuring that TeslaMate never stores or processes your actual login credentials, and it delegates all MFA and CAPTCHA handling to Tesla's official infrastructure.

### How do I know if my tokens have expired?

When tokens expire or become invalid, TeslaMate's API calls return `401 Unauthorized` errors. The application automatically detects these failures, clears the stored tokens using `TeslaMate.Auth.delete_tokens/0`, and redirects you to the sign-in page to obtain fresh tokens.