Skip to content
Esc
navigateopen⌘Jpreview
Dashboard

Verify TOTP code

Check if a TOTP code is valid against any of the TOTP devices for a user.

POST/appid-{appId}/{tenantId}/recipe/totp/verify
Authorization
api-keyAPI key · headerrequired
The core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Path parameters
tenantIdstring
The tenant against which the request is made. If left empty, the default tenant will be used.
Header parameters
ridstring
cdi-versionstring
X.Y of the X.Y.Z CDI version.
Request body
application/json
userIduserIdrequired
totpstringrequired
The TOTP code to verify
allowUnverifiedDevicesbooleanrequired
Whether to allow verification against unverified devices
Responses
200Indicates success with the status property
One of:
object
statusstatusOK
Allowed:OK
object
statusstring
Allowed:INVALID_TOTP_ERROR
currentNumberOfFailedAttemptsnumber
Current number of failed verification attempts
maxNumberOfFailedAttemptsnumber
Maximum allowed failed verification attempts
object
statusstring
Allowed:UNKNOWN_USER_ID_ERROR
object
statusstring
Allowed:LIMIT_REACHED_ERROR
retryAfterMsnumber
Time in milliseconds to wait before retrying
currentNumberOfFailedAttemptsnumber
Current number of failed verification attempts
maxNumberOfFailedAttemptsnumber
Maximum allowed failed verification attempts
400error code 400
string
401error code 401
string
404error code 404
string
500error code 500
string
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/public/recipe/totp/verify" \
  -H "api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "userId": "fa7a0841-b533-4478-95533-0fde890c3483",
  "totp": "123456",
  "allowUnverifiedDevices": false
}'
Response
{
  "status": "OK"
}

API reference

API schema and response details