I struggled with this for weeks before finding the solution. The issue is that TC 13.1’s mobile app has a compatibility gap with MFA when performing workflow actions like ECN approvals. Here’s what you need to address:
MFA Method Compatibility Issue:
The mobile app version 13.1.2 has a known bug where it doesn’t properly refresh the MFA authentication token during approval workflows. After the initial MFA login succeeds, the app caches the primary authentication token but fails to include the MFA validation token in subsequent API calls for approval actions. This is why desktop works (browser handles token refresh automatically) but mobile fails.
Solution - Upgrade and Configure:
First, upgrade to mobile app version 13.1.4 or later. This version includes the critical fix for MFA token handling during workflow operations. If you’re using SMS-based MFA, the token validity window needs to be extended in your MFA provider settings - set it to at least 10 minutes instead of the default 5 minutes to accommodate the approval workflow’s multiple API calls.
Mobile App Version Compatibility:
Verify your mobile app backend configuration. In the MobileServerConfig.xml file on your Teamcenter server, ensure these settings are present:
<mfa-token-refresh enabled="true"/>
<session-extension-for-workflows value="600"/>
<approval-api-timeout value="45000"/>
The session-extension-for-workflows parameter is crucial - it extends the authentication session specifically for approval workflows to prevent timeout during the multi-step approval process.
Network Connectivity Requirements:
The mobile app needs consistent network connectivity throughout the approval process because it makes 3-4 sequential API calls (validate approval authority, check ECN status, submit approval, trigger notifications). If users switch between WiFi and cellular during this sequence, the MFA token validation can fail. Configure your mobile device management to prefer WiFi for the Teamcenter app, or ensure your MFA provider supports token validation across network transitions.
Additional Configuration:
In your MFA provider settings, whitelist these specific mobile API endpoints that handle approvals:
- `/tc/mobile/api/workflow/approve
- `/tc/mobile/api/notification/action
- `/tc/mobile/api/ecn/approve
Also check your firewall logs - some corporate firewalls treat rapid sequential API calls from mobile devices as suspicious activity and throttle them, causing the 30-second timeout you’re seeing.
After implementing these changes, have users completely log out and back in to the mobile app to refresh all cached tokens. The approval workflow should then work seamlessly with MFA enabled.
This draft is based on general Teamcenter knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.