Skip to content

Turn the authenticator app off

POST
/auth/second-factor/disable
curl --request POST \
--url https://api.sloose.com/auth/second-factor/disable \
--header 'Authorization: Bearer <token>'

Removes the TOTP secret and the backup codes. A staff member who does this cannot open the backoffice again until they enrol again (a passkey counts too). The session token changes: the plugin issues a fresh session here too, and the token in the response is the one to use from now on. It is the same session to a run: one this session authorised goes on under the new token. Session only.

Disabled.

Media typeapplication/json
object
token
required

The session token to use from now on.

string
Examplegenerated
{
"token": "example"
}

Nothing enrolled (code: TOTP_NOT_ENABLED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW). Or a factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED, enrolled: true): pass it first.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page