# The site sends a code. You type it. The job goes on.

One-time codes by e-mail or SMS, authenticator prompts, approval screens: a second factor is a step only the account owner can finish. Kaabist pauses the job there, emails a link to you (or the teammate or customer who owns the account), and resumes the program the moment the code is typed.

## The problem

A headless script cannot read your phone. Teams either switch the second factor off, which security will not accept, or babysit every run, which defeats the automation.

## Wait for the code, in the program

await_input names what the job needs and how long it may wait. The value arrives as a variable the next step types in.

```
{ "await_input": { "name": "otp", "type": "secret",
    "collect": "hosted",
    "hosted": { "notify": "email", "to": "{{inputs.approver}}" } } },
{ "fill": "#otp", "value": "{{vars.otp}}" }
```

## A link, not an account

The address you set in the step (yours, a teammate's or your customer's) gets an e-mail with a link to a page on app.kaab.ist. It shows what the job is waiting for and a field for the code. No Kaabist account needed.

## Or answer from your own code

If the code reaches a system you control, post it to the job yourself. Subscribe to job.awaiting_input to know when one is needed.

```
curl -X POST https://api.kaab.ist/v1/jobs/job_8KqV2/input \
  -H "Authorization: Bearer $KAAB_API_KEY" \
  -d '{"otp": "481207"}'
```

## Ask less often

Save the session after the second factor. Later jobs reuse it and skip the whole login, so you are asked for a code only when the session finally expires.

## Questions

### How long can a job wait for the code?

As long as the step allows: 24 hours by default, up to 7 days. The browser is not kept open that long; the job resumes from its checkpoint.
