Frequently Asked Questions - Authenticator


Q 01: What is HBZ Authenticator?

HBZ Authenticator is tool used by Habib Bank AG Zurich - UAE for secure two-factor authentication based on Time-Based One-Time Password (TOTP), for secure login to access HBZ web-services.

Q 02: Who can use HBZ Authenticator?

Habib Bank AG Zurich customers, who are subscribed to HBZweb services and have HBZweb Username with the Bank with appropriate profile. (Maker or Checker)

Q 03: How do I get HBZ Authenticator?

To get HBZ Authenticator, download HBZ App from Apple Store or Google Play. HBZ Authenticator is an integral part of the HBZ App. When starting the HBZ App, click on the menu button on the top-left corner and select HBZ Authenticator.

Q 04: What is TOTP?

TOTP is short form of Time-Based One-Time Password (TOTP), which will be made available for two-factor authentication of users as they access the HBZ web-services.

Q 05: What is secure two-factor authentication?

Two-factor authentication is a layer of security designed to prevent someone from accessing your account, even if they have your password. Two-factor authentication requires you to verify your identity using a random sequence of 6-digit number generated by HBZ Authenticator.

Q 06: Why should I set up my account for Two-factor authentication?

Passwords may be guessed or cracked. Thus, for better protection, we encourage you to use two-factor authentication. For secured login using HBZ Authenticator, you will be required to provide a security code generated by your HBZ App, along with Username, Password & and Challenge Code (captcha) when using HBZweb.

Q 07: Do I need 2FA security code for login on HBZ App on my phone?

NO, If you choose to login from your HBZ App you will not required the security code from HBZ Authenticator, HBZ App required OTP to process transactions.

Q 08: Do I need to install an app to enable 2FA if I already have HBZ App on my Smartphone?

If you already have latest HBZ App, there's no need to download any additional App. HBZ Authenticator is an integral part of HBZ App. Getting set up is easy--- launch the HBZ App and click on Authenticator in left side menu and follow the on screen instructions for setup.

Q 09: Why do I need to install HBZ App application to enable two-factor authentication? Can my security code be texted to me instead?

HBZweb login supports Time-based One-Time Password (TOTP) method for two-factor authentication, which requires HBZ Authenticator, which is available under HBZ App only. Without the application, two-factor authentication will not work for your account.

Q 10: Why would I want to enable two-factor authentication?

Requiring these different kinds of factors for authentication makes it much harder for people to pretend to be you. Not only do they need to figure out your password, they also need to steal your mobile phone. Accounts protected with Multifactor Authentication are usually much safer than those protected with only a password. Multifactor Authentication can help combat fraud and protect you.

Q 11: What if I don't have a Smartphone or other mobile device?

HBZ Authenticator works only with HBZ App installed on a Smartphone.

Q 12: Can I set up 2FA for multiple users/devices?

Yes, two-factor authentication can be set up for multiple devices. You can set up as many devices as you need.

Q 13: How does the HBZ Authenticator App works?

Once you click HBZ Authenticator from the left-side menu of HBZ App, it will prompt to enter Username to get the code for secure login, if you have already completed the first-time registration steps, as mentioned under question “How do I set up HBZ Authenticator on a new phone?”

Q 14: Can I request new Secure Key for HBZweb login to initiate funds transfer request?

Issuance of new Secure Key has been stopped with immediate effect for both existing and new customers. Use HBZ Authenticator for secure login to initiate your web fund transfer requests.

Q 15: Currently I am using Secure Key for secure login on HBZweb, can I still use the same Secure Key instead of HBZ Authenticator?

Users can continue using Secure Key option to access the secured HBZweb services but we encourage all users to migrate to the HBZ Authenticator as we would soon be discontinuing the use of Secure Key.

Q 16: What are the benefits of the HBZ Authenticator?

HBZ Authenticator works on TOTP algorithm (global standard and used by most international and local banks) and furthermore this will eliminate the need to carry Secure Key or any other additional gadget. Your smart phone will generate the code for secure login to initiate web-based transactions.

Q 17: I have multiple users enabled for my/our account(s), should all of them register?

Yes, all HBZweb users enabled for your(s) account must register on their choice of mobile device separately using their own Usernames and credentials?

Q 18: I have 5 different companies account with your bank, do I need to register 5 different mobile for these companies account?

No, multiple entities owner have the option either to register single mobile phone device for all entities/usernames or register separate mobile device for each/few accounts to obtain code for secure login. Each entity will have its own username with the Bank with appropriate profile (maker or checker).

Q 19: Do I need to register all my group companies’ usernames for HBZ Authenticator?

Yes, You need to register all your group companies one by one but the choice of device is entirely yours. You can register only those entities that have their username with the Bank with appropriate profile (maker or checker) enabled for HBZ web login.

Q 20: What are the salient features of HBZ Authenticator?

Some of the salient features of the new HBZ Authenticator are as follows:

  1. 1) No need to carry `Secure Key` or any other additional gadget. Client`s smart phone will generate the code for secure login to initiate web-based transactions.
  2. It works on TOTP algorithm (global standard and used by most international and local banks);
  3. Multiple entities owner may register one mobile phone for all entities/usernames to obtain code for secure login. Each entity will have its own username with the Bank with appropriate profile (maker or checker);
  4. After one-time registration is done, the HBZ Authenticator works even without the requirement of `Data/WiFi` package.
  5. You can also register multiple mobile phones for same username to obtain code for secure login.

Q 21: I am not using HBZ App, how do I set up HBZ Authenticator?

Download the latest HBZ application from app store (Apple Store or Google Play) and follow the below steps for registering a new mobile device for the time-based one-time password (TOTP) generation:

  1. 1) Once downloaded Launch HBZ mobile App.
  2. Enter HBZ web username, password and captcha (challenge code) in the next screen and press "Login".
  3. Enter OTP received on your registered mobile number for registering the device for login.
  4. Once the device is registered, click on the Menu on top left of your screen.
  5. Then select the "Authenticator" button.
  6. Enter HBZ web user name in the next screen and press "Generate Code".
  7. Press “OK” to register user for the usage of Authenticator.
  8. Enter HBZ web username, password and captcha (challenge code) and click "Login".
  9. Enter the OTP received on your registered mobile number to complete the registration.
  10. Now the device is ready to use for generating HBZ Authenticator code.

This completes the initial registration phase when a first-time user tries to access the Authenticator. The TOTP mobile application will save the user account and generates an authentication code for when required by the client.

Q 22: I am already using HBZ App, how I can register for HBZ Authenticator?

Please follow the below steps for HBZ Authenticator registration:

  1. 1) Update your HBZ Mobile App to our latest version from app store (Apple Store or Google Play).
  2. Click on the Menu on top left of your screen.
  3. Select the "Authenticator" button.
  4. Enter HBZ web username in the next screen and press "Generate Code".
  5. Press “OK” to register user for the usage of Authenticator.
  6. Enter HBZ web username, password and captcha (challenge code) and click "Login".
  7. Enter the OTP received on your registered mobile number to complete the registration.
  8. Now the device is ready to use for generating HBZ Authenticator code.

Q 23: To register my mobile device for HBZ Authenticator, how HBZ will send me the OTP?

OTP (One-Time-Password) will be sent to your registered mobile with Habib Bank AG Zurich – UAE, to complete your HBZ Authenticator registration process.

Q 24: How to Login using HBZ Authenticator?

Please follow the below steps for secure Login using HBZ Authenticator :

  1. 1) Open the HBZ mobile App and press HBZ Authenticator from top left Menu option.
  2. Enter HBZ web username and press generate code.
  3. Go to http://www.habibbank.com/ and press Login.
  4. Enter user name, password and captcha (challenge code).
  5. In HBZ Authenticator field enter code generated from HBZ Authenticator on your HBZ mobile App.
  6. Click "Login" and you are ready to go!

Q 25: What type of customers can use HBZ Authenticator?

HBZ Authenticator can be used by all customers who are registered for HBZ web services.

Q 26: Can I use my existing Authenticator App to generate HBZ Authentication code?

HBZ Authenticator code cannot be generated from any other App. It can only be generated using HBZ mobile App.

Q 27: If I restore my device from a backup, What will happen?

HBZ App will work with the same device back-up. In case of any issue please delete existing App and re-register the device for HBZ Authenticator.

Q 28: How do I remove my account from the HBZ mobile App?

Please call our call center and provide the description (brand, type & model) of the device and our team will do the needful for you.

Q 29: Can I transfer my HBZ Authenticator to a new phone?

No you cannot transfer HBZ Authenticator from one device to another device.

Q 30: Once code is generated from Authenticator, how long it will be valid?

The code will be valid for 2 minutes.

Q 31: What will happen if I update my mobile software to newer version?

You need not to worry as HBZ App & HBZ Authenticator will be compatible with new version of software. If required our IT team will release the upgrade of HBZ App.

Q 32: What if my cell phone runs out of power?

You need to wait to charge your mobile phone sufficiently to use & generate code. Alternatively you can register a new/back-up device to generate code.

Q 33: What if my cell phone is stolen?

Please call our call center and provide the description (brand, type & model) of the device and our team will help you to remove the stolen device to generate authenticator for your HBZ web account.

Q 34: If I have further enquiries on HBZ Authenticator and HBZ App, whom should I contact?

You may contact our call center or your Relationship Manager, alternatively you can visit your respective branch.