Skip to content

Start authenticator enrollment

POST
/v1/auth/totp/enroll
curl --request POST \
--url http://localhost:8080/v1/auth/totp/enroll

Generates a fresh TOTP secret for the signed-in user and returns it once, as a base32 setup key and an otpauth:// URI for authenticator apps. Nothing is enforced until the first code is confirmed, so an abandoned enrollment can never lock anyone out. 409 when an authenticator is already active.

OK

Media typeapplication/json

Shown once at enrollment: the setup key and the otpauth URI authenticator apps accept.

object
secret
required
string
otpauthUri
required
string
Examplegenerated
{
"secret": "example",
"otpauthUri": "example"
}