Answer an MFA challenge

Submits a proof against the named factor. On success, records MFA elevation for the challenge's exact requiredFor purpose until that purpose's bounded expiry. Other elevated operations require their own purpose-specific proof.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
Body Params

MFA factor resource id. New factors use the canonical 22-character Wingspan id. The legacy mfa_email_ form remains accepted so factors auto-enrolled before WIN-15277 can still be acted on without rewriting persisted Spanner primary keys.

string
string
string
string
Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json