put/users/@me/mfa/webauthn/two-factor

Set WebAuthn two-factor authentication

Choose whether registered passkeys are required as a second factor when signing in with email and password. Enabling requires at least one registered credential and mints backup codes when the account has none. Requires sudo mode verification.

set_webauthn_two_factor

Request body

application/json

json
{
  "type": "object",
  "properties": {
    "enabled": {
      "type": "boolean",
      "description": "Whether registered passkeys count as a second factor when logging in"
    },
    "password": {
      "description": "Account password for sudo verification",
      "$ref": "#/components/schemas/PasswordType"
    },
    "mfa_method": {
      "description": "MFA method to use for verification",
      "x-enumNames": [
        "TOTP",
        "WebAuthn"
      ],
      "x-enumDescriptions": [
        "Time-based one-time password authentication via authenticator app",
        "Security key or biometric authentication"
      ],
      "enum": [
        "totp",
        "webauthn"
      ],
      "type": "string"
    },
    "mfa_code": {
      "description": "MFA verification code from an authenticator app",
      "type": "string"
    },
    "webauthn_response": {
      "description": "WebAuthn authentication response",
      "$ref": "#/components/schemas/WebAuthnAuthenticationResponse"
    },
    "webauthn_challenge": {
      "description": "WebAuthn challenge string",
      "type": "string"
    }
  },
  "required": [
    "enabled"
  ]
}

Responses

200

Success

json
{
  "type": "object",
  "properties": {
    "user": {
      "description": "The updated account",
      "$ref": "#/components/schemas/UserPrivateResponse"
    },
    "backup_codes": {
      "anyOf": [
        {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "code": {
                "type": "string",
                "description": "The backup code"
              },
              "consumed": {
                "type": "boolean",
                "description": "Whether the code has been used"
              }
            },
            "required": [
              "code",
              "consumed"
            ],
            "additionalProperties": false
          }
        },
        {
          "type": "null"
        }
      ],
      "description": "Backup codes minted by this call, or null when none were minted"
    }
  },
  "required": [
    "user",
    "backup_codes"
  ],
  "additionalProperties": false
}
400

Bad Request - The request was malformed or contained invalid data

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
401

Unauthorized - Authentication is required or the token is invalid

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
403

Forbidden - You do not have permission to perform this action

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
429

Too Many Requests - You are being rate limited

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    },
    "retry_after": {
      "type": "number",
      "description": "Seconds to wait before retrying"
    },
    "global": {
      "type": "boolean",
      "description": "Whether this is a global rate limit"
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
500

Internal Server Error - An unexpected error occurred

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}