Security and sign-in
Start two-factor during sign-in
POST
/api/auth/mfa/enrolWhen the workspace requires two-factor and the person has none yet.
#Authentication
Public
No credential. Public routes are rate limited per address.
Carries the short-lived MFA ticket that POST /api/auth/login returned, not a session.