Guide: MFA API Reference

MFA endpoints and flow expectations for password and OAuth sign-ins.

  • GET /api/v1/auth/mfa/status
  • POST /api/v1/auth/mfa/totp/enroll/start
  • POST /api/v1/auth/mfa/totp/enroll/verify
  • POST /api/v1/auth/mfa/challenge/verify
  • POST /api/v1/auth/mfa/backup-codes/regenerate
  • POST /api/v1/auth/mfa/disable
  • GET /api/v1/auth/mfa/trusted-devices
  • POST /api/v1/auth/mfa/trusted-devices/{device_id}/revoke
  • POST /api/v1/auth/mfa/recovery/email/start
  • POST /api/v1/auth/mfa/recovery/email/verify