Email a code to enable or disable 2FA
Requires current password; recipient is always the account's stored email, never request input. Eight-digit code expires in five minutes and allows five guesses. At most five issues per user/hour, twenty per IP/hour and one per purpose/minute. 202 is queue acceptance, not delivery. Only provider-acknowledged codes can be redeemed.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
currentPassword*stringpassword0 <= length <= 72purpose*string"ENABLE""DISABLE"Email challenge queued
*/*- response
Second-factor challenge without tokens. EMAIL returns a challengeId and expiry; TOTP returns null for both and sends no email.
challengeId?|EMAIL challenge UUID; null when channel is TOTP.
uuidchannel?stringRequired second factor. TOTP accepts totpCode or one unused recoveryCode.
"EMAIL""TOTP"expiresAt?|EMAIL code expiry; null when channel is TOTP. Authenticator codes use a 30-second time step.
date-timecurl -X POST 'https://api.monetaryai.uz/api/v1/me/security/email-2fa/challenges' \ -H 'Content-Type: application/json' \ -d '{ "currentPassword": "pa$$word", "purpose": "ENABLE"}'{ "challengeId": "007cfdcc-a46d-4340-a4c6-216ec2e4009c", "channel": "EMAIL", "expiresAt": "2019-08-24T14:15:22Z"}Generate Google Authenticator QR and manual setup key POST
Requires current password. Returns a locally generated PNG QR and otpauth URI (SHA1, 6 digits, 30s), never an external QR service. Pending setup expires after 10 minutes; repeating setup resumes it without resetting the guess budget. Does not enable 2FA until confirm succeeds. Secrets must not be logged or cached. Already enabled returns 409; unavailable encryption returns 503.
Confirm disabling email 2FA POST
Requires current password and a separate acknowledged DISABLE code. A login or enrollment code cannot disable 2FA. Invalidates all refresh sessions and access JWTs; login again.