---
title: "Verify a fresh second factor for the current session"
method: POST
path: "/identity/step_ups"
tags: ["identity", "security"]
---

# Verify a fresh second factor for the current session

`POST /identity/step_ups`

## Request body

- IdentityStepUpCreateInput
  - `code` string, required — Current authenticator code.
  - `method` 'totp', required — Second factor to prove. Only totp.

## Response `200`

OK

- IdentityStepUpCreateOutput
  - `verified_ts` string, date-time, required — When the code was verified and recorded.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `409` — Conflict
- `429` — Too Many Requests
- `default` — Error response.

## Changes

- **2026-10-05** `5b02334be03f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/stablesea/apis/stable-sea-backend/changes/identity/step_ups/post.md)

---

[API](https://skmtc.dev/stablesea/apis/stable-sea-backend.md) · [All operations](https://skmtc.dev/stablesea/apis/stable-sea-backend/llms.txt) · [OpenAPI document](https://skmtc.dev/stablesea/apis/stable-sea-backend/revisions/352f74da5030?raw)
