Skip to content

Pass the second factor for this session

POST
/auth/second-factor/verify
curl --request POST \
--url https://api.sloose.com/auth/second-factor/verify \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "code": "492817" }'

A TOTP from the authenticator app, or one of the backup codes (which is then spent). On success this session is marked as having passed the factor now, which is what the staff routes ask for. Five wrong codes lock the factor for fifteen minutes (code: SECOND_FACTOR_LOCKED). Session only.

Media typeapplication/json
object
code
required

A six-digit TOTP from the authenticator app, or one backup code.

string
>= 6 characters <= 64 characters
Example
492817

Passed.

Media typeapplication/json

A write that carries nothing back.

object
ok
required
boolean
Example
{
"ok": true
}

Nothing enrolled (code: TOTP_NOT_ENABLED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

The code is wrong (code: INVALID_CODE), or there is no live session (code: AUTH_REQUIRED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Locked after too many wrong codes (code: SECOND_FACTOR_LOCKED, with until).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page