How TeslaMate Handles MFA and CAPTCHA in Its Authentication Flow

TeslaMate delegates MFA and CAPTCHA challenges entirely to Tesla's official authentication endpoint, managing only the resulting OAuth tokens that users obtain through external login flows.

TeslaMate is an open-source data logger for Tesla vehicles that interacts with the Tesla API. Unlike applications that implement custom authentication layers, TeslaMate's authentication flow relies entirely on externally obtained OAuth tokens, bypassing the need to handle sensitive MFA challenges or CAPTCHA verification internally.

External OAuth Token Collection

TeslaMate does not present its own login form for credentials. Instead, the SigninLive module in lib/teslamate_web/live/signin_live/index.ex prompts users to provide an access token and refresh token pair obtained by authenticating directly with Tesla's official service at https://auth.tesla.com.

The live view initializes with a changeset for token validation:


# lib/teslamate_web/live/signin_live/index.ex – UI collects tokens

def mount(_params, _session, socket) do
  %{
    api: get_api(socket),
    page_title: gettext("Sign in"),
    changeset: Auth.change_tokens(),
    provider: System.get_env("TESLA_AUTH_HOST", "https://auth.tesla.com")
  }
  |> then(&{:ok, assign(socket, &1)})
end

This design means any MFA prompts (SMS codes, authenticator apps) or CAPTCHA challenges occur entirely on Tesla's servers. TeslaMate never processes username/password combinations or displays CAPTCHA widgets.

Token Storage and Validation

Once submitted, the tokens pass through the TeslaMate.Auth context located in lib/teslamate/auth.ex. The save/1 function validates and persists the token pair using the TeslaMate.Auth.Tokens schema defined in lib/teslamate/auth/tokens.ex.


# lib/teslamate/auth.ex – saving tokens

def save(%{token: access, refresh_token: refresh}) do
  attrs = %{access: access, refresh: refresh}
  case get_tokens() do
    nil   -> create_tokens(attrs)
    token -> update_tokens(token, attrs)
  end
end

The system stores both the access token for API requests and the refresh token for maintaining long-term access.

Automatic Token Refresh and Expiration Handling

TeslaMate automatically refreshes access tokens before they expire using TeslaApi.Auth.refresh/1 in lib/tesla_api/auth.ex. This function exchanges the stored refresh token for a new access token through Tesla's /oauth2/v1/token endpoint.

When a refresh fails—typically because the user must re-authenticate due to an expired MFA session or revoked credentials—the application handles the 401 Unauthorized response by clearing stored tokens and returning to the sign-in prompt.


# lib/tesla_api/auth.ex – token refresh (handles 401)

def refresh(%Auth{} = auth) do
  # Calls Tesla's /oauth2/v1/token endpoint with the stored refresh token.

  # On success returns a new %Auth{}; on failure the caller treats it as

  # an unauthorized state and clears stored tokens.

end

The TeslaMate.Auth.delete_tokens/0 function removes invalid credentials from the database, forcing the user to obtain fresh tokens through Tesla's authentication flow again.

Security Architecture Benefits

By delegating MFA and CAPTCHA handling to Tesla's official infrastructure, TeslaMate avoids several security risks:

  • No credential storage: Usernames and passwords never pass through TeslaMate's servers
  • No challenge logic: The application doesn't implement CAPTCHA solving or MFA verification algorithms
  • Upstream compliance: Automatically inherits Tesla's security updates and authentication requirements

This architecture ensures that sensitive authentication challenges remain within Tesla's controlled environment while TeslaMate focuses exclusively on API data logging.

Summary

  • TeslaMate does not implement MFA or CAPTCHA checks internally
  • Users must obtain OAuth tokens externally from https://auth.tesla.com, completing any required MFA or CAPTCHA challenges there
  • The SigninLive view in lib/teslamate_web/live/signin_live/index.ex collects only the resulting access and refresh tokens
  • TeslaMate.Auth validates and stores tokens via lib/teslamate/auth.ex and lib/teslamate/auth/tokens.ex
  • Automatic token refresh occurs through TeslaApi.Auth.refresh/1, with failures triggering token deletion via delete_tokens/0
  • Invalid tokens result in 401 Unauthorized responses, prompting users to re-authenticate through Tesla's official flow

Frequently Asked Questions

Does TeslaMate support automatic MFA code entry?

No. TeslaMate does not interact with the MFA process at all. Users must complete any multi-factor authentication steps directly on Tesla's official authentication website before copying the resulting OAuth tokens into TeslaMate.

What happens when my Tesla account requires CAPTCHA verification?

CAPTCHA challenges are handled entirely by Tesla's authentication servers. Since TeslaMate only accepts tokens that you obtain externally, you will complete any CAPTCHA requirements during the token generation process on Tesla's site, not within the TeslaMate interface.

Why does TeslaMate ask for tokens instead of my Tesla username and password?

TeslaMate uses an OAuth-based authentication flow that requires access and refresh tokens. This approach enhances security by ensuring that TeslaMate never stores or processes your actual login credentials, and it delegates all MFA and CAPTCHA handling to Tesla's official infrastructure.

How do I know if my tokens have expired?

When tokens expire or become invalid, TeslaMate's API calls return 401 Unauthorized errors. The application automatically detects these failures, clears the stored tokens using TeslaMate.Auth.delete_tokens/0, and redirects you to the sign-in page to obtain fresh tokens.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →