Skip to content

Verify the first code, which turns enrolment on

POST
/auth/second-factor/enrol/verify
curl --request POST \
--url https://api.sloose.com/auth/second-factor/enrol/verify \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "code": "492817" }'

The first code from the authenticator app proves the secret reached it. From here the person is enrolled, and this session counts as having passed the factor. The session token may change: the plugin issues a fresh session on the first verification, and the token in the response is the one to use from now on. It is the same session to a run: one this session authorised goes on under the new token. Session only.

Media typeapplication/json
object
code
required

The six-digit TOTP the authenticator app shows for the secret just enrolled.

string
>= 6 characters <= 64 characters
Example
492817

Enrolled.

Media typeapplication/json
object
token
required

The session token to use from now on.

string
Examplegenerated
{
"token": "example"
}

The code is wrong (code: INVALID_CODE) — a 400 and not a 401, because the session is fine and the page shows it inline; not enrolling (code: TOTP_NOT_ENABLED); or already enrolled (code: TOTP_ALREADY_ENABLED) — this is the first code only; a later one is /verify.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW). Or a factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED, enrolled: true): pass it first.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page