Activate Google Authenticator using its six-digit code
Requires current password, enrollmentId and TOTP code. Only a valid unexpired setup can activate. Returns ten one-use recovery codes ONCE; only hashes are stored. Explicitly replaces existing email 2FA, revokes all sessions/JWTs across memberships, and requires login again. The enrollment code is consumed; use the NEXT 30-second code for login. Five guesses per five minutes; replay and foreign enrollment rejected.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
code*string[0-9]{6}1 <= lengthcurrentPassword*stringpassword0 <= length <= 72enrollmentId*stringuuidEnabled, recovery codes returned once; login again
*/*- response
recoveryCodes?array<string>curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/authenticator/confirm' \ -H 'Content-Type: application/json' \ -d '{ "code": "string", "currentPassword": "pa$$word", "enrollmentId": "883e2903-3e2f-407c-ae2a-1274a4137945"}'{ "recoveryCodes": [ "string" ]}Read account 2FA status GET
Global identity setting applies across all tenant memberships. No password or code is returned.
Disable Google Authenticator using password and second factor POST
Requires current password and one fresh six-digit code OR one unused recoveryCode. Removes the secret/recovery codes and revokes every session/JWT. Password reset never disables TOTP. Login again after success.