Created on
01-06-2026
06:44 AM
Edited on
01-09-2026
02:06 AM
By
Jean-Philippe_P
| Description | This article describes the technical process of FortiToken activation, FortiToken Mobile and FortiToken Hardware. |
| Scope | FortiAuthenticator, FortiGate, FortiPAM, FortiProxy. |
| Solution |
This article is focuses on FortiAuthenticator for centralized token management. FortiAuthenticator can provision (assign) tokens manually and automatically. FortiGate, FortiPAM and FortiProxy can only provision the tokens manually, but each product follows the same technical process, despite the UI differences between the products.
Hardware and mobile tokens both display a one-time-password used as an authentication factor for the product where that token was provisioned. The OTP is calculated with a random and unique cryptographic value, so-called 'seed'. Both the end user device and the authenticating device's OTP calculation must match.
FortiToken Mobile online activation:
The activation process for any Mobile token follows these steps:
FortiToken Mobile offline activation:
The Offline Activation feature for mobile tokens is only available for FortiAuthenticator, not FortiGate, FortiPAM, or FortiProxy. Also note that FortiProxy does not support FortiToken Mobile license import. Only the integrated trial tokens, as well as FortiToken Cloud, are supported. See this document: FortiTokens for more information.
FortiToken Hardware: The activation process for Hardware tokens is different. The FortiToken Hardware is a physical token (FTK2x0y), and the seed used to calculate the OTP in the display is already present in that token. User activation for the token is not required, only token import and administrative assignment.
The FortiToken Hardware import step (Step 1. above) requires the FortiAuthenticator to be online. Alternatively, since the seeds for each token are static (burned into the hardware token), Fortinet can supply seed files for the tokens. This allows offline import for hardware tokens. The offline activation feature for hardware tokens is available for FortiAuthenticator, FortiGate, FortiPAM, and FortiProxy. See the following documentation for more information.
Some FortiToken Hardware SKUs (tokens with serial numbers beginning in FTK211...) do not allow downloading the seed or requesting the seed file. Instead, the seeds are shipped on an included CD together with the hardware tokens. Fortinet does not retain the seed file for these SKUs: if the seed file is lost, the token can no longer be imported. See this article: Technical Tip: Lost seed file for FortiToken Hardware with CD. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.