---
title: "Get backup codes for multi-factor authentication"
method: POST
path: "/users/@me/mfa/backup-codes"
tags: ["Users"]
---

# Get backup codes for multi-factor authentication

`POST /users/@me/mfa/backup-codes`

Generate and retrieve new backup codes for account recovery. Requires sudo mode verification. Old codes are invalidated.

## Request body

- MfaBackupCodesRequest
  - `regenerate` boolean, required — Whether to regenerate backup codes
  - `password` string
  - `mfa_method` 'totp' | 'webauthn' — MFA method to use for verification
  - `mfa_code` string — MFA verification code from an authenticator app
  - `webauthn_response` object — WebAuthn authentication response
  - `webauthn_challenge` string — WebAuthn challenge string

## Response `200`

Success

- MfaBackupCodesResponse
  - `backup_codes` object[], required — List of backup codes
    - `code` string, required — The backup code
    - `consumed` boolean, required — Whether the code has been used

## Other responses

- `400` — Bad Request - The request was malformed or contained invalid data
- `401` — Unauthorized - Authentication is required or the token is invalid
- `403` — Forbidden - You do not have permission to perform this action
- `429` — Too Many Requests - You are being rate limited
- `500` — Internal Server Error - An unexpected error occurred

---

[API](https://skmtc.dev/fluxer/apis/fluxer-api.md) · [All operations](https://skmtc.dev/fluxer/apis/fluxer-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/fluxer/fluxer-api/revisions/d9c706133cc5/schema)
