Skip to main content
POST
Verify TOTP enrollment

Authorizations

Authorization
string
header
required

Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.

Body

application/json
enrollmentToken
string
required

Opaque enrollmentToken returned by begin TOTP enrollment. Submit it before expiresAt.

Required string length: 1 - 4096
verificationCode
string
required

Six-digit code from the authenticator configured with the enrollment secret. Send as a string to preserve leading zeros.

Pattern: ^[0-9]{6}$

Response

The TOTP factor was verified for the authenticated Account.

enrolled
boolean
required

Always true after the TOTP factor has been successfully verified and enrolled.

factorId
string
required

Identifier of a TOTP authentication factor, prefixed with auth_factor_.

Maximum string length: 128
Pattern: ^auth_factor_[A-Za-z0-9]+$