MonetaryAI / Docs
API ReferenceAccount security

Email a code to enable or disable 2FA

Requires current password; recipient is always the account's stored email, never request input. Eight-digit code expires in five minutes and allows five guesses. At most five issues per user/hour, twenty per IP/hour and one per purpose/minute. 202 is queue acceptance, not delivery. Only provider-acknowledged codes can be redeemed.

POST
/api/v1/me/security/email-2fa/challenges

Authorization

bearerAuth
headerAuthorizationBearer <token>

Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.

Request Body

application/json
  1. body
currentPassword*string
Formatpassword
Length0 <= length <= 72
purpose*string
Value in"ENABLE""DISABLE"

Response Body

Email challenge queued

*/*
  1. response

Second-factor challenge without tokens. EMAIL returns a challengeId and expiry; TOTP returns null for both and sends no email.

challengeId?|

EMAIL challenge UUID; null when channel is TOTP.

Formatuuid
channel?string

Required second factor. TOTP accepts totpCode or one unused recoveryCode.

Value in"EMAIL""TOTP"
expiresAt?|

EMAIL code expiry; null when channel is TOTP. Authenticator codes use a 30-second time step.

Formatdate-time
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/email-2fa/challenges' \  -H 'Content-Type: application/json' \  -d '{  "currentPassword": "pa$$word",  "purpose": "ENABLE"}'
{  "challengeId": "007cfdcc-a46d-4340-a4c6-216ec2e4009c",  "channel": "EMAIL",  "expiresAt": "2019-08-24T14:15:22Z"}