curl --request POST \
--url https://api.photon.codes/v1/account/security/mfa/totp/verify \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enrollmentToken": "<string>",
"verificationCode": "<string>"
}
'import requests
url = "https://api.photon.codes/v1/account/security/mfa/totp/verify"
payload = {
"enrollmentToken": "<string>",
"verificationCode": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({enrollmentToken: '<string>', verificationCode: '<string>'})
};
fetch('https://api.photon.codes/v1/account/security/mfa/totp/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.photon.codes/v1/account/security/mfa/totp/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'enrollmentToken' => '<string>',
'verificationCode' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.photon.codes/v1/account/security/mfa/totp/verify"
payload := strings.NewReader("{\n \"enrollmentToken\": \"<string>\",\n \"verificationCode\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.photon.codes/v1/account/security/mfa/totp/verify")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"enrollmentToken\": \"<string>\",\n \"verificationCode\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.photon.codes/v1/account/security/mfa/totp/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"enrollmentToken\": \"<string>\",\n \"verificationCode\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"enrolled": true,
"factorId": "<string>"
}{
"code": "MFA_ENROLLMENT_INVALID",
"status": 400,
"title": "MFA Enrollment Invalid",
"type": "https://photon.codes/docs/problems/mfa-enrollment-invalid"
}{
"code": "NOT_AUTHENTICATED",
"status": 401,
"title": "Not Authenticated",
"type": "https://photon.codes/docs/problems/not-authenticated"
}{
"code": "FORBIDDEN",
"status": 403,
"title": "Forbidden",
"type": "https://photon.codes/docs/problems/forbidden"
}{
"code": "MFA_ENROLLMENT_EXPIRED",
"status": 410,
"title": "MFA Enrollment Expired",
"type": "https://photon.codes/docs/problems/mfa-enrollment-expired"
}{
"code": "VALIDATION_FAILED",
"issues": [
{
"code": "invalid_type",
"location": "json",
"message": "Expected a string.",
"path": "/name"
}
],
"status": 422,
"title": "Request Validation Failed",
"type": "https://photon.codes/docs/problems/validation-failed"
}{
"code": "INTERNAL_ERROR",
"status": 500,
"title": "Internal Server Error",
"type": "https://photon.codes/docs/problems/internal-error"
}{
"code": "UPSTREAM_FAILURE",
"status": 502,
"title": "Upstream Service Failure",
"type": "https://photon.codes/docs/problems/upstream-failure"
}{
"code": "UPSTREAM_UNAVAILABLE",
"status": 503,
"title": "Upstream Service Unavailable",
"type": "https://photon.codes/docs/problems/upstream-unavailable"
}{
"code": "UPSTREAM_TIMEOUT",
"status": 504,
"title": "Upstream Service Timeout",
"type": "https://photon.codes/docs/problems/upstream-timeout"
}Verify TOTP enrollment
Requires a first-party interactive Account credential authenticated no more than 300 seconds ago.
curl --request POST \
--url https://api.photon.codes/v1/account/security/mfa/totp/verify \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enrollmentToken": "<string>",
"verificationCode": "<string>"
}
'import requests
url = "https://api.photon.codes/v1/account/security/mfa/totp/verify"
payload = {
"enrollmentToken": "<string>",
"verificationCode": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({enrollmentToken: '<string>', verificationCode: '<string>'})
};
fetch('https://api.photon.codes/v1/account/security/mfa/totp/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.photon.codes/v1/account/security/mfa/totp/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'enrollmentToken' => '<string>',
'verificationCode' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.photon.codes/v1/account/security/mfa/totp/verify"
payload := strings.NewReader("{\n \"enrollmentToken\": \"<string>\",\n \"verificationCode\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.photon.codes/v1/account/security/mfa/totp/verify")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"enrollmentToken\": \"<string>\",\n \"verificationCode\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.photon.codes/v1/account/security/mfa/totp/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"enrollmentToken\": \"<string>\",\n \"verificationCode\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"enrolled": true,
"factorId": "<string>"
}{
"code": "MFA_ENROLLMENT_INVALID",
"status": 400,
"title": "MFA Enrollment Invalid",
"type": "https://photon.codes/docs/problems/mfa-enrollment-invalid"
}{
"code": "NOT_AUTHENTICATED",
"status": 401,
"title": "Not Authenticated",
"type": "https://photon.codes/docs/problems/not-authenticated"
}{
"code": "FORBIDDEN",
"status": 403,
"title": "Forbidden",
"type": "https://photon.codes/docs/problems/forbidden"
}{
"code": "MFA_ENROLLMENT_EXPIRED",
"status": 410,
"title": "MFA Enrollment Expired",
"type": "https://photon.codes/docs/problems/mfa-enrollment-expired"
}{
"code": "VALIDATION_FAILED",
"issues": [
{
"code": "invalid_type",
"location": "json",
"message": "Expected a string.",
"path": "/name"
}
],
"status": 422,
"title": "Request Validation Failed",
"type": "https://photon.codes/docs/problems/validation-failed"
}{
"code": "INTERNAL_ERROR",
"status": 500,
"title": "Internal Server Error",
"type": "https://photon.codes/docs/problems/internal-error"
}{
"code": "UPSTREAM_FAILURE",
"status": 502,
"title": "Upstream Service Failure",
"type": "https://photon.codes/docs/problems/upstream-failure"
}{
"code": "UPSTREAM_UNAVAILABLE",
"status": 503,
"title": "Upstream Service Unavailable",
"type": "https://photon.codes/docs/problems/upstream-unavailable"
}{
"code": "UPSTREAM_TIMEOUT",
"status": 504,
"title": "Upstream Service Timeout",
"type": "https://photon.codes/docs/problems/upstream-timeout"
}Authorizations
Account Service Key, prefixed with pho_ask_, sent as Authorization: Bearer <key>. Acts on behalf of its owning account, subject to the permissions and credential restrictions of each operation. Account access tokens and OAuth grants also use the Bearer header. In organizations that require SSO, Account Service Keys are not accepted for managing the organization's SSO settings, deleting the organization, or checking whether it can be deleted.
Body
Opaque enrollmentToken returned by begin TOTP enrollment. Submit it before expiresAt.
1 - 4096Six-digit code from the authenticator configured with the enrollment secret. Send as a string to preserve leading zeros.
^[0-9]{6}$Response
The TOTP factor was verified for the authenticated Account.
Was this page helpful?