Disable Google Authenticator using password and second factor
Requires current password and one fresh six-digit code OR one unused recoveryCode. Removes the secret/recovery codes and revokes every session/JWT. Password reset never disables TOTP. Login again after success.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
code?string[0-9]{6}currentPassword*stringpassword0 <= length <= 72recoveryCode?string(?i)[a-z2-7]{4}(?:-?[a-z2-7]{4}){3}Disabled, login again
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/authenticator/disable' \ -H 'Content-Type: application/json' \ -d '{ "currentPassword": "pa$$word"}'Activate Google Authenticator using its six-digit code POST
Requires current password, enrollmentId and TOTP code. Only a valid unexpired setup can activate. Returns ten one-use recovery codes ONCE; only hashes are stored. Explicitly replaces existing email 2FA, revokes all sessions/JWTs across memberships, and requires login again. The enrollment code is consumed; use the NEXT 30-second code for login. Five guesses per five minutes; replay and foreign enrollment rejected.
Generate Google Authenticator QR and manual setup key POST
Requires current password. Returns a locally generated PNG QR and otpauth URI (SHA1, 6 digits, 30s), never an external QR service. Pending setup expires after 10 minutes; repeating setup resumes it without resetting the guess budget. Does not enable 2FA until confirm succeeds. Secrets must not be logged or cached. Already enabled returns 409; unavailable encryption returns 503.