---
title: "Confirm authenticator enrolment with a code; returns a fresh token and recovery codes. (Roles: user)"
method: POST
path: "/auth/2fa/totp/confirm"
tags: ["Authentication"]
---

# Confirm authenticator enrolment with a code; returns a fresh token and recovery codes. (Roles: user)

`POST /auth/2fa/totp/confirm`

## Request body

- TwoFactorTotpConfirmPayload
  - `totp_code` string, required

## Response `200`

Success

- TwoFactorEnrollResponse
  - `token` string — Fresh token. Enrolling revokes every existing session, so the client must adopt this one immediately or log itself out.
  - `recovery_codes` string[] — Shown exactly once. EMPTY when the account already had recovery codes (a second factor type was added) — render that as "your existing recovery codes still apply", never as an empty list of ten.

## Other responses

- `400` — Error
- `429` — Too many failed second-factor attempts

## Changes

- **2026-09-01** `37a21589e770` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/ludo/apis/ludo-ai-api/changes/auth/2fa/totp/confirm/post.md)

---

[API](https://skmtc.dev/ludo/apis/ludo-ai-api.md) · [All operations](https://skmtc.dev/ludo/apis/ludo-ai-api/llms.txt) · [OpenAPI document](https://skmtc.dev/ludo/apis/ludo-ai-api/revisions/a6d8dcc39b12?raw)
