Take every second factor off somebody
const url = 'https://api.sloose.com/staff/people/c1d2e3f4/second-factor/reset';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"reason":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/staff/people/c1d2e3f4/second-factor/reset \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "reason": "example" }'Backoffice route: a staff session, or ADMIN_TOKEN. The remedy for a person who has lost the authenticator app and the backup codes: the app, its codes and its lock, and every passkey are removed, and the second-factor stamp comes off every session they hold. Their sessions keep working — a sign-in never needed a factor — and they enrol again from Your account, since the first enrolment is the one change that needs no factor. For a staff member it also means the backoffice stays shut until they have. Written down as user.second_factor.reset, with the reason.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The person
Example
c1d2e3f4The person
Request Bodyrequired
Section titled “Request Bodyrequired”object
Why — the support ticket, usually. Required; it goes on the record.
Examplegenerated
{ "reason": "example"}Responses
Section titled “Responses”Reset. Both false and zero when nothing was enrolled.
object
An authenticator app was enrolled, and is gone.
How many passkeys were removed.
Examplegenerated
{ "totp": true, "passkeys": 1}The request — its body or its query — did not match the schema. issues carries the Zod issue list.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}A bearer that is neither the token nor a live session (code: AUTH_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}A customer’s session, an API token, or no bearer at all — not staff, and not the ADMIN_TOKEN (code: ADMIN_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No such person, or it is not visible to this session.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}