Pass the second factor for this session
const url = 'https://api.sloose.com/auth/second-factor/verify';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"code":"492817"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/second-factor/verify \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "code": "492817" }'A TOTP from the authenticator app, or one of the backup codes (which is then spent). On success this session is marked as having passed the factor now, which is what the staff routes ask for. Five wrong codes lock the factor for fifteen minutes (code: SECOND_FACTOR_LOCKED). Session only.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
A six-digit TOTP from the authenticator app, or one backup code.
Example
492817Responses
Section titled “Responses”Passed.
A write that carries nothing back.
object
Example
{ "ok": true}Nothing enrolled (code: TOTP_NOT_ENABLED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}The code is wrong (code: INVALID_CODE), or there is no live session (code: AUTH_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}Locked after too many wrong codes (code: SECOND_FACTOR_LOCKED, with until).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}