Your second factor
const url = 'https://api.sloose.com/auth/second-factor';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.sloose.com/auth/second-factor \ --header 'Authorization: Bearer <token>'What this person has enrolled — a TOTP, passkeys — and whether THIS session has passed one recently. Session only.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”The status.
object
A TOTP is enrolled and its first code verified.
How many passkeys are registered.
totp or at least one passkey.
When THIS session last passed a second factor; null if never.
Whether that was within the window the staff routes require (twelve hours).
Whether this person’s staff role requires one on the backoffice routes.
Examplegenerated
{ "totp": true, "passkeys": 1, "enrolled": true, "verifiedAt": "example", "recent": true, "required": true}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}