MonetaryAI / Docs
API ReferenceAccount security

Activate Google Authenticator using its six-digit code

Requires current password, enrollmentId and TOTP code. Only a valid unexpired setup can activate. Returns ten one-use recovery codes ONCE; only hashes are stored. Explicitly replaces existing email 2FA, revokes all sessions/JWTs across memberships, and requires login again. The enrollment code is consumed; use the NEXT 30-second code for login. Five guesses per five minutes; replay and foreign enrollment rejected.

POST
/api/v1/me/security/authenticator/confirm

Authorization

bearerAuth
headerAuthorizationBearer <token>

Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.

Request Body

application/json
  1. body
code*string
Match[0-9]{6}
Length1 <= length
currentPassword*string
Formatpassword
Length0 <= length <= 72
enrollmentId*string
Formatuuid

Response Body

Enabled, recovery codes returned once; login again

*/*
  1. response
recoveryCodes?array<string>
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/authenticator/confirm' \  -H 'Content-Type: application/json' \  -d '{  "code": "string",  "currentPassword": "pa$$word",  "enrollmentId": "883e2903-3e2f-407c-ae2a-1274a4137945"}'
{  "recoveryCodes": [    "string"  ]}