Skip to main content
POST
`POST /v1/control/mfa/enroll`: starts or restarts enrolment.

Authorizations

esectra_session
string
cookie
required

A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.

Response

Enrolment secret and otpauth URI

The secret to put into an authenticator app.

otpauth_uri
string
required

The URI to render as a QR code.

secret
string
required

The same secret, for someone typing it in by hand.