Auth

Sign in — second factor (e-mailed code)

Step two of a 2FA login: the code from the e-mail, or — when an authenticator is enrolled — the code it shows. Bearer: the `pending_2fa` token from login; the caller must hold the `2fa` role. With a proven authenticator the login completes (`200`, session pair; `refresh_token: null` and the `pending_workspace` token for two or more workspaces). Without one: `202` with a token that opens authenticator enrolment. A code is good for one attempt. Same contract as `POST /api/v1/auth/authenticate`.

POST
/api/v2/auth/authenticate

Authorization

BearerAuthObject
AuthorizationBearer <token>

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

curl -X POST "https://example.com/api/v2/auth/authenticate" \  -H "Content-Type: application/json" \  -d '{    "email": "string",    "auth_code": "123456"  }'
Empty
Empty
Empty
Empty
Empty
Empty