MFA Verify
/v1/auth/mfa/verifyPart of Auth.
Complete the second factor with a passkey assertion or a recovery code.
Authentication
This operation does not require an API key.
Request body
Required, application/json.
| Field | Type | Description |
|---|---|---|
mfa_tokenrequired | string | Token from a login that returned mfa_required |
assertionoptional | object | WebAuthn assertion (browser JSON, opaque) |
recovery_codeoptional | string | Single-use recovery code |
Example request
curl -X POST "https://api.robosystems.ai/v1/auth/mfa/verify" \
-H "Content-Type: application/json" \
-d '{
"mfa_token": "string"
}'Responses
200 Successful Response
| Field | Type | Description |
|---|---|---|
userrequired | object | User information |
orgoptional | object | Organization information (personal org created automatically on registration) |
messagerequired | string | Success message |
statusoptional | string | Login flow state: authenticated (token present), or a passkey MFA step is required before a session is issued (mfa_token present) One of: Default: |
mfa_tokenoptional | string | Short-lived token authorizing the MFA second step or forced enrollment; present only when status is not 'authenticated' |
tokenoptional | string | JWT authentication token (optional for cookie-based auth) |
expires_inoptional | integer | Token expiry time in seconds from now |
refresh_thresholdoptional | integer | Recommended refresh threshold in seconds before expiry |
| Status | Meaning |
|---|---|
| 400 | Invalid request |
| 401 | Verification failed |
| 422 | Validation Error |
| 429 | Rate limit exceeded |
| 500 | Internal server error |