Confirm email 2FA enrollment
Requires current password and acknowledged ENABLE code. Invalidates every session and access token for the global identity; login again with password and email code. Wrong, expired, unacknowledged, foreign or reused challenges return 401.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
challengeId*stringuuidcode*string[0-9]{8}1 <= lengthcurrentPassword*stringpassword0 <= length <= 72Email 2FA enabled; login again
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/email-2fa/enable' \ -H 'Content-Type: application/json' \ -d '{ "challengeId": "007cfdcc-a46d-4340-a4c6-216ec2e4009c", "code": "string", "currentPassword": "pa$$word"}'Confirm disabling email 2FA POST
Requires current password and a separate acknowledged DISABLE code. A login or enrollment code cannot disable 2FA. Invalidates all refresh sessions and access JWTs; login again.
Change password using current password POST
Requires matching confirmation and the current password. Atomically invalidates all refresh sessions, outstanding email challenges and access JWTs across every membership. Login again after success.