Cloudflare OTP login for HAS

Wondering if anyone has setup their HAS with Cloudflare One-time PIN. For context, I’m running my HAS with Cloudflare tunnel so that I can have access to my home devices when I’m not at home, and I was trying to set this up to add an extra layer of security for my domain so that one can only see what the server is about if they get the OTP from one of the allowlisted emails.

It seems to work fine with web but not quite for the companion app, a chrome browser pop up for the cloudflare sign-in but then it never gets back to the app.

FWIW, this is how I was trying to setup the OTP https://www.crosstalksolutions.com/cloudflare-tunnel-easy-setup/, tunnel works fine if I don’t have OTP on