MonetaryAI / Docs
API ReferenceAccount security

Generate Google Authenticator QR and manual setup key

Requires current password. Returns a locally generated PNG QR and otpauth URI (SHA1, 6 digits, 30s), never an external QR service. Pending setup expires after 10 minutes; repeating setup resumes it without resetting the guess budget. Does not enable 2FA until confirm succeeds. Secrets must not be logged or cached. Already enabled returns 409; unavailable encryption returns 503.

POST
/api/v1/me/security/authenticator/setup

Authorization

bearerAuth
headerAuthorizationBearer <token>

Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.

Request Body

application/json
  1. body
currentPassword*string
Formatpassword
Length0 <= length <= 72

Response Body

Pending enrollment and QR generated

*/*
  1. response
enrollmentId?string
Formatuuid
expiresAt?string
Formatdate-time
otpauthUri?string
qrDataUrl?string
secret?string
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/authenticator/setup' \  -H 'Content-Type: application/json' \  -d '{  "currentPassword": "pa$$word"}'
{  "enrollmentId": "883e2903-3e2f-407c-ae2a-1274a4137945",  "expiresAt": "2019-08-24T14:15:22Z",  "otpauthUri": "string",  "qrDataUrl": "string",  "secret": "string"}