Skip to content

Your second factor

GET
/auth/second-factor
curl --request GET \
--url https://api.sloose.com/auth/second-factor \
--header 'Authorization: Bearer <token>'

What this person has enrolled — a TOTP, passkeys — and whether THIS session has passed one recently. Session only.

The status.

Media typeapplication/json
object
totp
required

A TOTP is enrolled and its first code verified.

boolean
passkeys
required

How many passkeys are registered.

integer
enrolled
required

totp or at least one passkey.

boolean
verifiedAt
required

When THIS session last passed a second factor; null if never.

string | null
recent
required

Whether that was within the window the staff routes require (twelve hours).

boolean
required
required

Whether this person’s staff role requires one on the backoffice routes.

boolean
Examplegenerated
{
"totp": true,
"passkeys": 1,
"enrolled": true,
"verifiedAt": "example",
"recent": true,
"required": true
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page