MINARA

Disable TOTP

POST /v1/security/totp/disable — Turns TOTP off without removing the device binding. Requires both a fresh TOTP code AND a fresh email verification code

POST /v1/security/totp/disable

Turns TOTP off without removing the device binding. Requires both a fresh TOTP code AND a fresh email verification code so a stolen authenticator alone cannot disable 2FA.

MethodPOST
Path/v1/security/totp/disable
AuthAuthorization: Bearer <token> required when GATEWAY_AUTH_TOKEN is set
Categoryauth

Notes

Failures answer with { error, status, message }, where error is the stable machine code. A rejected second factor maps to one of a stable set: invalid_totp, totp_required, invalid_email_code, email_code_required, verification_locked (too many wrong email codes; the message names the wait), totp_state_conflict (the account is already in the requested state), totp_not_provisioned (no secret generated yet), or rate_limited. Request-shape rejections answer 400 with totp_code_required, totp_and_email_required, or settings_payload_invalid depending on the endpoint. Anything the gateway cannot classify keeps that endpoint's own <action>_failed code with a generic message; the upstream wording stays in the server log.

On this page