Verify TOTP code
Check if a TOTP code is valid against any of the TOTP devices for a user.
POST
/appid-{appId}/{tenantId}/recipe/totp/verifyAuthorization
api-keyAPI key · headerrequiredThe core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Path parameters
tenantIdstringThe tenant against which the request is made. If left empty, the default tenant will be used.
Header parameters
ridstringcdi-versionstringX.Y of the X.Y.Z CDI version.
Request body
application/jsonuserIduserIdrequiredtotpstringrequiredThe TOTP code to verify
allowUnverifiedDevicesbooleanrequiredWhether to allow verification against unverified devices
Responses
200Indicates success with the status property
One of:
object
statusstatusOKAllowed:
OKobject
statusstringAllowed:
INVALID_TOTP_ERRORcurrentNumberOfFailedAttemptsnumberCurrent number of failed verification attempts
maxNumberOfFailedAttemptsnumberMaximum allowed failed verification attempts
object
statusstringAllowed:
UNKNOWN_USER_ID_ERRORobject
statusstringAllowed:
LIMIT_REACHED_ERRORretryAfterMsnumberTime in milliseconds to wait before retrying
currentNumberOfFailedAttemptsnumberCurrent number of failed verification attempts
maxNumberOfFailedAttemptsnumberMaximum allowed failed verification attempts
400error code 400
string401error code 401
string404error code 404
string500error code 500
stringTry it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/public/recipe/totp/verify" \
-H "api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"totp": "123456",
"allowUnverifiedDevices": false
}'const response = await fetch("/appid-{appId}/public/recipe/totp/verify", {
method: "POST",
headers: {
"api-key": "YOUR_API_KEY",
"Content-Type": "application/json"
},
body: JSON.stringify({
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"totp": "123456",
"allowUnverifiedDevices": false
})
});import requests
response = requests.post(
"/appid-{appId}/public/recipe/totp/verify",
headers={
"api-key": "YOUR_API_KEY",
"Content-Type": "application/json"
},
json={
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"totp": "123456",
"allowUnverifiedDevices": False
},
)Response
{
"status": "OK"
}"string""Invalid API key""Not Found""Internal Error"