Enable TOTP
POST /v1/security/totp/enable — Activates TOTP after the user proves they configured the authenticator by submitting a fresh 6-digit code. Step 3 of the
POST /v1/security/totp/enable
Activates TOTP after the user proves they configured the authenticator by submitting a fresh 6-digit code. Step 3 of the enable wizard.
| Method | POST |
| Path | /v1/security/totp/enable |
| Auth | Authorization: Bearer <token> required when GATEWAY_AUTH_TOKEN is set |
| Category | auth |
Notes
Failures answer with { error, status, message }, where error is the stable machine code. A rejected second factor maps to one of a stable set: invalid_totp, totp_required, invalid_email_code, email_code_required, verification_locked (too many wrong email codes; the message names the wait), totp_state_conflict (the account is already in the requested state), totp_not_provisioned (no secret generated yet), or rate_limited. Request-shape rejections answer 400 with totp_code_required, totp_and_email_required, or settings_payload_invalid depending on the endpoint. Anything the gateway cannot classify keeps that endpoint's own <action>_failed code with a generic message; the upstream wording stays in the server log.