Skip to content
Torii docs

Start MFA enrollment during an enforced sign-in

POST
/_torii/auth/mfa/enroll
curl --request POST \
--url 'https://your-app.torii.so/_torii/auth/mfa/enroll?_is_native=false' \
--header 'Content-Type: application/json' \
--data '{ "challengeToken": "example" }'

For a login that returned mfa_enrollment_required: mints a pending TOTP secret keyed on the challenge token. Returns the otpauth URI + manual key; no session yet.

Origin
string
Host
string
_is_native
boolean
Media type application/json
object
challengeToken
required
string
Example generated
{
"challengeToken": "example"
}

OK

Media type application/json
object
Example generated
{}