Authentication

Confirm authenticator enrolment with a code; returns a fresh token and recovery codes. (Roles: user)

post/auth/2fa/totp/confirm

Request body

totp_codestring required

Response

Success

tokenstring

Fresh token. Enrolling revokes every existing session, so the client must adopt this one immediately or log itself out.

recovery_codesstring[]

Shown exactly once. EMPTY when the account already had recovery codes (a second factor type was added) — render that as "your existing recovery codes still apply", never as an empty list of ten.

Changes

Changed in 1 of the 17 revisions of this API.1