Skip to content

Confirm authenticator enrollment

POST
/v1/auth/totp/confirm
curl --request POST \
--url http://localhost:8080/v1/auth/totp/confirm \
--header 'Content-Type: application/json' \
--data '{ "code": "example" }'

Proves possession with a first code from the app. From here, password sign-in requires an authenticator code whenever auth.login_totp_enabled is on. 401 for a wrong code, 409 when nothing is enrolled; confirming twice is a no-op.

Media typeapplication/json
object
code
string
Examplegenerated
{
"code": "example"
}

No Content