Verify the first code, which turns enrolment on
const url = 'https://api.sloose.com/auth/second-factor/enrol/verify';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"code":"492817"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/second-factor/enrol/verify \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "code": "492817" }'The first code from the authenticator app proves the secret reached it. From here the person is enrolled, and this session counts as having passed the factor. The session token may change: the plugin issues a fresh session on the first verification, and the token in the response is the one to use from now on. It is the same session to a run: one this session authorised goes on under the new token. Session only.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
The six-digit TOTP the authenticator app shows for the secret just enrolled.
Example
492817Responses
Section titled “Responses”Enrolled.
object
The session token to use from now on.
Examplegenerated
{ "token": "example"}The code is wrong (code: INVALID_CODE) — a 400 and not a 401, because the session is fine and the page shows it inline; not enrolling (code: TOTP_NOT_ENABLED); or already enrolled (code: TOTP_ALREADY_ENABLED) — this is the first code only; a later one is /verify.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW). Or a factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED, enrolled: true): pass it first.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}