Skip to content
Esc
navigateopen⌘Jpreview
Dashboard

Verify TOTP device

Mark a TOTP device as verified if the given TOTP code is valid for that device.

POST/appid-{appId}/{tenantId}/recipe/totp/device/verify
Authorization
api-keyAPI key · headerrequired
The core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Path parameters
tenantIdstring
The tenant against which the request is made. If left empty, the default tenant will be used.
Header parameters
ridstring
cdi-versionstring
X.Y of the X.Y.Z CDI version.
Request body
application/json
userIduserIdrequired
deviceNamestringrequired
Name of the TOTP device to verify
totpstringrequired
The TOTP code to verify
Responses
200Indicates success with the status property
One of:
object
statusstatusOK
Allowed:OK
wasAlreadyVerifiedboolean
Indicates if the device was already verified
object
statusstring
Allowed:UNKNOWN_DEVICE_ERROR
object
statusstring
Allowed:INVALID_TOTP_ERROR
currentNumberOfFailedAttemptsnumber
Current number of failed verification attempts
maxNumberOfFailedAttemptsnumber
Maximum allowed failed verification attempts
object
statusstring
Allowed:LIMIT_REACHED_ERROR
retryAfterMsnumber
Time in milliseconds to wait before retrying
currentNumberOfFailedAttemptsnumber
Current number of failed verification attempts
maxNumberOfFailedAttemptsnumber
Maximum allowed failed verification attempts
400error code 400
string
401error code 401
string
404error code 404
string
500error code 500
string
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/public/recipe/totp/device/verify" \
  -H "api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "userId": "fa7a0841-b533-4478-95533-0fde890c3483",
  "deviceName": "My Authy App",
  "totp": "123456"
}'
Response
{
  "status": "OK",
  "wasAlreadyVerified": false
}

API reference

API schema and response details