Verification

Send Verification Code

Changed on

Initiates MFA setup or verification by sending a code to the user. For TOTP-based MFA (Google Authenticator), returns a QR code and secret.

post/verification/send-code

Request

  • Base URL: http://localhost:8080/api/v1
  • URL: http://localhost:8080/api/v1/verification/send-code
  • Auth: API key in cookie jwt

Request body

user_idstring uuid required

The UUID of the user requesting verification

method'totp' | 'email' | 'sms'

Verification method (defaults to totp for Google Authenticator)

Example request

{
  "user_id": "f20e5948-01ba-4113-b453-db05d8bde3bc",
  "method": "totp"
}

Response

Verification code sent successfully

messagestring
qr_codestring

Base64-encoded QR code image for TOTP setup (only for totp method)

secretstring

TOTP secret key for manual entry (only for totp method)

backup_codesstring[]

One-time backup codes for account recovery

Example response

{
  "message": "Verification code sent successfully",
  "qr_code": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAA...",
  "secret": "JBSWY3DPEHPK3PXP",
  "backup_codes": [
    "ABCD-1234",
    "EFGH-5678",
    "IJKL-9012"
  ]
}

Changes