Start enrolling an authenticator app
const url = 'https://api.sloose.com/auth/second-factor/enrol';const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/second-factor/enrol \ --header 'Authorization: Bearer <token>'Makes a TOTP secret and a set of backup codes for this person. The secret is returned once as an otpauth:// URI for the authenticator app; the backup codes are returned once and never again. Nothing is enforced until the first code is verified (/enrol/verify). Session only.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”The secret, as a URI, and the backup codes — shown once.
object
Examplegenerated
{ "totpURI": "example", "backupCodes": [ "example" ]}Already enrolled and verified (code: TOTP_ALREADY_ENABLED): disable first.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW). Or a factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED, enrolled: true): pass it first.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}