Browse the API reference

MFA Verify

post/v1/auth/mfa/verify

Part of Auth.

Complete the second factor with a passkey assertion or a recovery code.

Authentication

This operation does not require an API key.

Request body

Required, application/json.

FieldTypeDescription
mfa_tokenrequiredstring

Token from a login that returned mfa_required

assertionoptionalobject

WebAuthn assertion (browser JSON, opaque)

recovery_codeoptionalstring

Single-use recovery code

Example request

curl
curl -X POST "https://api.robosystems.ai/v1/auth/mfa/verify" \
  -H "Content-Type: application/json" \
  -d '{
  "mfa_token": "string"
}'

Responses

200 Successful Response

FieldTypeDescription
userrequiredobject

User information

orgoptionalobject

Organization information (personal org created automatically on registration)

messagerequiredstring

Success message

statusoptionalstring

Login flow state: authenticated (token present), or a passkey MFA step is required before a session is issued (mfa_token present)

One of: authenticated, mfa_required, mfa_enrollment_required

Default: authenticated

mfa_tokenoptionalstring

Short-lived token authorizing the MFA second step or forced enrollment; present only when status is not 'authenticated'

tokenoptionalstring

JWT authentication token (optional for cookie-based auth)

expires_inoptionalinteger

Token expiry time in seconds from now

refresh_thresholdoptionalinteger

Recommended refresh threshold in seconds before expiry

StatusMeaning
400Invalid request
401Verification failed
422Validation Error
429Rate limit exceeded
500Internal server error