Turn the authenticator app off
const url = 'https://api.sloose.com/auth/second-factor/disable';const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/second-factor/disable \ --header 'Authorization: Bearer <token>'Removes the TOTP secret and the backup codes. A staff member who does this cannot open the backoffice again until they enrol again (a passkey counts too). The session token changes: the plugin issues a fresh session here too, and the token in the response is the one to use from now on. It is the same session to a run: one this session authorised goes on under the new token. Session only.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”Disabled.
object
The session token to use from now on.
Examplegenerated
{ "token": "example"}Nothing enrolled (code: TOTP_NOT_ENABLED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW). Or a factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED, enrolled: true): pass it first.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}