Skip to main content
POST
Begin TOTP enrollment

Authorizations

Authorization
string
header
required

Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.

Body

application/json

Empty object. Enrollment uses the authenticated Account and accepts no additional fields.

Response

One-time TOTP setup material and enrollment continuation.

enrollmentToken
string
required

Opaque, short-lived MFA enrollment continuation token.

Maximum string length: 4096
expiresAt
string<date-time>
required

UTC expiry time of the enrollment token, in RFC 3339 format. Complete verification before this time.

Example:

"2026-01-01T00:00:00.000Z"

factorId
string
required

Identifier of a TOTP authentication factor, prefixed with auth_factor_.

Maximum string length: 128
Pattern: ^auth_factor_[A-Za-z0-9]+$
secret
string
required

One-time TOTP secret. Never log, cache, or persist it.

Required string length: 1 - 256
uri
string
required

One-time authenticator setup URI containing the TOTP secret.

Required string length: 1 - 4096
Pattern: ^otpauth:\/\/.*