Skip to content

Mideye+ App: Push & Offline TOTP Setup Guide

Users with smartphones can download the Mideye+ app to authenticate using push notifications and offline TOTP codes instead of SMS. There is no extra charge for using the Mideye+ app.


  1. Open the Mideye+ app. When prompted with “Mideye+ Would Like to Send You Notifications”, tap Allow.

  2. Enter the phone number in international format (e.g., +46735084555) and press Next.

    Enter phone number

  3. Make an authentication attempt to the corporate resource (VPN, Citrix portal, etc.) protected with Mideye.

    Authenticate to resource

  4. When the activation SMS arrives, open it and tap the link. The app displays “Activation successful” and shows an OTP.

    Activation successful


  1. Open the Mideye+ app and agree to the terms.

    Agree to terms

  2. Enter the phone number in international format and press Next.

    Enter phone number

  3. Make an authentication attempt to the protected corporate resource.

    Authenticate to resource

  4. When the activation SMS arrives, open it and tap the link.

    Activation successful


Once activated, the app replaces SMS-based OTPs. When you authenticate, the OTP is delivered via data traffic and appears as a notification:

OTP notification

This works even without mobile network coverage, as long as the phone has internet access.


When both network coverage and internet are unavailable, Mideye presents a challenge code (e.g., “Phone not reachable, please sign xxxxxx”):

Challenge message

  1. Open the Mideye+ app and tap Manual signature at the bottom.

    Manual signature

  2. Tap Offline OTP and enter the challenge code.

    Enter challenge

  3. Enter the resulting OTP at the login screen.

    OTP result


Touch Accept simplifies authentication to a single approve/reject action. It does not use RADIUS challenge-response, enabling two-factor authentication on services that don’t support it.

  1. Navigate to Directory SettingsLDAP Profiles.
  2. Edit the LDAP profile → Authentication tab.
  3. Set Default authentication type to one of:
    • 6 — Touch only (no fallback)
    • 7 — Touch-Plus (fallback to OTP via Mideye+)
    • 8 — Touch-Mobile (fallback to SMS OTP)

LDAP profile authentication type

When the user authenticates, they receive a push notification to approve or deny the login:

Touch Accept notification


If manual signing returns a failed authentication, the RADIUS client timeout is likely set below 35 seconds. Increase the timeout on the RADIUS client.

The user may have denied notification permissions during initial setup.

iPhone: Settings → Notifications → Mideye+ → Enable Allow Notifications.

Enable notifications

Android: Settings vary by manufacturer. Check the app notification settings.

Android battery saving mode blocks notifications

Section titled “Android battery saving mode blocks notifications”

Exclude Mideye+ from battery optimization:

  1. Go to SettingsBatteryUnmonitored Apps.
  2. Tap Add apps, select Mideye+, and tap Done.

Battery optimization exclusion