Skip to main content
POST
`POST /v1/control/mfa/confirm`: proves the app works, and finishes enrolment.

Authorizations

esectra_session
string
cookie
required

A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.

Body

application/json

A code being presented.

code
string

Six digits from the authenticator app.

recovery_code
string

Or one recovery code, when the app is gone.

Response

Recovery codes, shown exactly once

The recovery codes, shown exactly once.

recovery_codes
string[]
required

Store these somewhere safe; they are not retrievable later.