MINARA

Unbind TOTP device

POST /v1/security/totp/unbind — Irrevocably removes the authenticator binding — re-enabling requires a fresh scan + verify cycle. Same dual-factor (TOTP

POST /v1/security/totp/unbind

Irrevocably removes the authenticator binding — re-enabling requires a fresh scan + verify cycle. Same dual-factor (TOTP + email) requirement as disable.

MethodPOST
Path/v1/security/totp/unbind
AuthAuthorization: Bearer <token> required when GATEWAY_AUTH_TOKEN is set
Categoryauth

Notes

Failures answer with { error, status, message }, where error is the stable machine code. A rejected second factor maps to one of a stable set: invalid_totp, totp_required, invalid_email_code, email_code_required, verification_locked (too many wrong email codes; the message names the wait), totp_state_conflict (the account is already in the requested state), totp_not_provisioned (no secret generated yet), or rate_limited. Request-shape rejections answer 400 with totp_code_required, totp_and_email_required, or settings_payload_invalid depending on the endpoint. Anything the gateway cannot classify keeps that endpoint's own <action>_failed code with a generic message; the upstream wording stays in the server log.

On this page