POST · Account & access
Confirm authenticator enrolment with a live code
Confirm authenticator enrolment with a live code
/api/v1/account/two-factor/confirm
This scope is inferred from the method and the endpoint's group — the OpenAPI document does
not carry one per operation. The wire is authoritative; whoami reports what your
token actually holds.
Description
Returns the new 2FA status plus confirmedMethodId. If it returns two_factor_enable_not_started, call enable_two_factor again first; if the code is wrong, read a fresh code from the app and retry.
Body
Send as application/json.
| Name | Type | Description |
|---|---|---|
code
required
|
string |
Pattern ^[0-9]{6}$.
|
Responses
The specification does not describe this response body; the note in the rail says what to expect.
Every non-2xx response is an RFC 7807 problem with a stable
code.
Commonly returned errors
The codes this operation reaches on its own path: the auth stack, its own validation and
ownership checks, and the transport. Not a closed set — a shared code from the
full registry can still surface. Each links to the code’s own page,
the same URL its type dereferences to.