Begin TOTP enrollment
Requires a first-party interactive Account credential authenticated no more than 300 seconds ago. Returns one-time secret material.
Authorizations
Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.
Body
Empty object. Enrollment uses the authenticated Account and accepts no additional fields.
Response
One-time TOTP setup material and enrollment continuation.
Opaque, short-lived MFA enrollment continuation token.
4096UTC expiry time of the enrollment token, in RFC 3339 format. Complete verification before this time.
"2026-01-01T00:00:00.000Z"
Identifier of a TOTP authentication factor, prefixed with auth_factor_.
128^auth_factor_[A-Za-z0-9]+$One-time TOTP secret. Never log, cache, or persist it.
1 - 256One-time authenticator setup URI containing the TOTP secret.
1 - 4096^otpauth:\/\/.*