Read account 2FA status
Global identity setting applies across all tenant memberships. No password or code is returned.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
OK
*/*- response
channel?stringemail2faEnabled?booleanemailDeliveryAvailable?booleanrecoveryCodesRemaining?integerint64totpAvailable?booleantotpEnabled?booleancurl -X GET 'https://api.monetaryai.uz/api/v1/me/security'{ "channel": "string", "email2faEnabled": true, "emailDeliveryAvailable": true, "recoveryCodesRemaining": 0, "totpAvailable": true, "totpEnabled": true}API Reference
Swagger sxemasidan avtomatik yaratilgan endpointlar.
Activate Google Authenticator using its six-digit code POST
Requires current password, enrollmentId and TOTP code. Only a valid unexpired setup can activate. Returns ten one-use recovery codes ONCE; only hashes are stored. Explicitly replaces existing email 2FA, revokes all sessions/JWTs across memberships, and requires login again. The enrollment code is consumed; use the NEXT 30-second code for login. Five guesses per five minutes; replay and foreign enrollment rejected.