Skip to content

Start enrolling an authenticator app

POST
/auth/second-factor/enrol
curl --request POST \
--url https://api.sloose.com/auth/second-factor/enrol \
--header 'Authorization: Bearer <token>'

Makes a TOTP secret and a set of backup codes for this person. The secret is returned once as an otpauth:// URI for the authenticator app; the backup codes are returned once and never again. Nothing is enforced until the first code is verified (/enrol/verify). Session only.

The secret, as a URI, and the backup codes — shown once.

Media typeapplication/json
object
totpURI
required
string
backupCodes
required
Array<string>
Examplegenerated
{
"totpURI": "example",
"backupCodes": [
"example"
]
}

Already enrolled and verified (code: TOTP_ALREADY_ENABLED): disable first.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW). Or a factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED, enrolled: true): pass it first.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page