Skip to content

Take every second factor off somebody

POST
/staff/people/{id}/second-factor/reset
curl --request POST \
--url https://api.sloose.com/staff/people/c1d2e3f4/second-factor/reset \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "reason": "example" }'

Backoffice route: a staff session, or ADMIN_TOKEN. The remedy for a person who has lost the authenticator app and the backup codes: the app, its codes and its lock, and every passkey are removed, and the second-factor stamp comes off every session they hold. Their sessions keep working — a sign-in never needed a factor — and they enrol again from Your account, since the first enrolment is the one change that needs no factor. For a staff member it also means the backoffice stays shut until they have. Written down as user.second_factor.reset, with the reason.

id
required

The person

string
Example
c1d2e3f4

The person

Media typeapplication/json
object
reason
required

Why — the support ticket, usually. Required; it goes on the record.

string
>= 1 characters <= 500 characters
Examplegenerated
{
"reason": "example"
}

Reset. Both false and zero when nothing was enrolled.

Media typeapplication/json
object
totp
required

An authenticator app was enrolled, and is gone.

boolean
passkeys
required

How many passkeys were removed.

integer
Examplegenerated
{
"totp": true,
"passkeys": 1
}

The request — its body or its query — did not match the schema. issues carries the Zod issue list.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

A bearer that is neither the token nor a live session (code: AUTH_REQUIRED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

A customer’s session, an API token, or no bearer at all — not staff, and not the ADMIN_TOKEN (code: ADMIN_REQUIRED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No such person, or it is not visible to this session.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page