Interlaken
API referenceIdentity and accessAuthentication

Complete a second-factor challenge

POST
/api/v1/auth/mfa/verify

Accepts an emailed code, an authenticator code or a recovery code. With remember_device the response sets the interlaken_device cookie for 30 days.

Authorization

AuthorizationBearer <token>

An access token from this zone's POST /oauth/token, or a session token from POST /api/v1/auth/login. Send it as Authorization: Bearer <token>.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/auth/mfa/verify" \  -H "Content-Type: application/json" \  -d '{    "challenge": "string",    "code": "string",    "remember_device": true  }'
{  "access_token": "string",  "expires_in": 0,  "id_token": "string",  "refresh_token": "string",  "scope": "string",  "token_type": "string"}