Confirm disabling email 2FA
Requires current password and a separate acknowledged DISABLE code. A login or enrollment code cannot disable 2FA. Invalidates all refresh sessions and access JWTs; login again.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
challengeId*stringuuidcode*string[0-9]{8}1 <= lengthcurrentPassword*stringpassword0 <= length <= 72Email 2FA disabled; login again
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/email-2fa/disable' \ -H 'Content-Type: application/json' \ -d '{ "challengeId": "007cfdcc-a46d-4340-a4c6-216ec2e4009c", "code": "string", "currentPassword": "pa$$word"}'Email a code to enable or disable 2FA POST
Requires current password; recipient is always the account's stored email, never request input. Eight-digit code expires in five minutes and allows five guesses. At most five issues per user/hour, twenty per IP/hour and one per purpose/minute. 202 is queue acceptance, not delivery. Only provider-acknowledged codes can be redeemed.
Confirm email 2FA enrollment POST
Requires current password and acknowledged ENABLE code. Invalidates every session and access token for the global identity; login again with password and email code. Wrong, expired, unacknowledged, foreign or reused challenges return 401.