Skip to content

Security and sign-in

Complete sign-in with a code

POST/api/auth/mfa

The ticket from a password sign-in, plus a TOTP or recovery code.

#Authentication

Public

No credential. Public routes are rate limited per address.

Carries the short-lived MFA ticket that POST /api/auth/login returned, not a session.