Skip to content

Security and sign-in

Start two-factor during sign-in

POST/api/auth/mfa/enrol

When the workspace requires two-factor and the person has none yet.

#Authentication

Public

No credential. Public routes are rate limited per address.

Carries the short-lived MFA ticket that POST /api/auth/login returned, not a session.