Send a code from the authenticator app or a passkey's response (start one with POST /v1/auth/passkeys/verification). Returns 10 new codes, shown once; the old codes stop working.
Authorization
bearer
Authorizationheader · stringrequired
Session token from POST /v1/auth/login with "transport": "bearer". Browsers use the session cookie that login sets instead.
Body
application/json
codestring
A code from the authenticator app
maxLength: 16
passkeyobject
A passkey's response, instead of code
2 fields
ceremony_tokenstringrequired
From POST /v1/auth/login/mfa/passkey when signing in, or POST /v1/auth/passkeys/verification when signed in
maxLength: 256
credentialobjectrequired
The PublicKeyCredential from navigator.credentials.get(), as JSON
Responses
errors: application/problem+json
200
OK
401
Unauthorized
409
Conflict
422
Unprocessable Entity
429
Too Many Requests
500
Internal Server Error
503
Service Unavailable
Match errors on the problem's code, which stays the same, not on its message.