Verify Session 2FA
POST/sessions/self/2fa-verifications
Complete a pending 2FA login by validating the TOTP code against a short-lived pending token issued at password/OAuth login. On success, return a new access token. The pending session expires after 15 minutes. Rate-limited to 10 requests per minute; any other failure returns verify_otp=false without details.
Request
Responses
- 200
- 422
Successful Response
OTP code input and secret are required for this endpoint.