> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# `POST /v1/control/mfa/confirm`: proves the app works, and finishes enrolment.

> The code is required before the enrolment counts. Without it, somebody who
mis-scanned the QR would be locked out of their own account with a
perfectly valid-looking secret on the server.



## OpenAPI

````yaml /openapi.json post /v1/control/mfa/confirm
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/control/mfa/confirm:
    post:
      tags:
        - Control
      summary: >-
        `POST /v1/control/mfa/confirm`: proves the app works, and finishes
        enrolment.
      description: >-
        The code is required before the enrolment counts. Without it, somebody
        who

        mis-scanned the QR would be locked out of their own account with a

        perfectly valid-looking secret on the server.
      operationId: confirm_handler
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CodeBody'
        required: true
      responses:
        '200':
          description: Recovery codes, shown exactly once
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RecoveryCodesBody'
        '401':
          description: No usable credentials
        '429':
          description: Too many failed attempts; carries Retry-After
        '503':
          description: A backing store could not be reached
      security:
        - session_cookie: []
components:
  schemas:
    CodeBody:
      type: object
      description: A code being presented.
      properties:
        code:
          type: string
          description: Six digits from the authenticator app.
        recovery_code:
          type: string
          description: Or one recovery code, when the app is gone.
    RecoveryCodesBody:
      type: object
      description: The recovery codes, shown exactly once.
      required:
        - recovery_codes
      properties:
        recovery_codes:
          type: array
          items:
            type: string
          description: Store these somewhere safe; they are not retrievable later.
  securitySchemes:
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````