Confirm MFA passcode
Verify a multi-factor authentication code and receive JWTs for the user’s companies.
curl --request POST \
--url https://api.fluid.app/api/authentication/confirm_mfa \
--header 'Content-Type: application/json' \
--data '
{
"uuid": "mfa_9f8c1b2a3d4e5f60",
"multi_factor_authentication": {
"verification_code": "123456"
}
}
'import requests
url = "https://api.fluid.app/api/authentication/confirm_mfa"
payload = {
"uuid": "mfa_9f8c1b2a3d4e5f60",
"multi_factor_authentication": { "verification_code": "123456" }
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
uuid: 'mfa_9f8c1b2a3d4e5f60',
multi_factor_authentication: {verification_code: '123456'}
})
};
fetch('https://api.fluid.app/api/authentication/confirm_mfa', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fluid.app/api/authentication/confirm_mfa",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'uuid' => 'mfa_9f8c1b2a3d4e5f60',
'multi_factor_authentication' => [
'verification_code' => '123456'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.fluid.app/api/authentication/confirm_mfa"
payload := strings.NewReader("{\n \"uuid\": \"mfa_9f8c1b2a3d4e5f60\",\n \"multi_factor_authentication\": {\n \"verification_code\": \"123456\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fluid.app/api/authentication/confirm_mfa")
.header("Content-Type", "application/json")
.body("{\n \"uuid\": \"mfa_9f8c1b2a3d4e5f60\",\n \"multi_factor_authentication\": {\n \"verification_code\": \"123456\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fluid.app/api/authentication/confirm_mfa")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"uuid\": \"mfa_9f8c1b2a3d4e5f60\",\n \"multi_factor_authentication\": {\n \"verification_code\": \"123456\"\n }\n}"
response = http.request(request)
puts response.read_body{
"authenticated": true,
"companies": [
{
"id": 123,
"name": "<string>",
"jwt": "<string>",
"shop_name": "<string>",
"logo_url": "<string>",
"primary_domain_hostname": "<string>"
}
],
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error_message": "<string>",
"errors": "<string>",
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error_message": "<string>",
"errors": "<string>",
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error_message": "<string>",
"errors": "<string>",
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}Query Parameters
Company subdomain used to pick which company receives the mfa_verified webhook. When omitted the company is resolved from the authenticated record's own companies.
Body
Response
Success
true once the submitted verification code matched, meaning the JWTs in companies are usable.
Top-level principal kind resolved by this login. Prefer the per-entry
companies[].auth_type when routing, since a user can be a rep in one
company and a customer in another.
user, customer, rep One entry per company the authenticated principal belongs to, each with its own bearer JWT. A single-company user gets a one-element array.
Show child attributes
Show child attributes
Response metadata (request id and generation timestamp).
Show child attributes
Show child attributes
curl --request POST \
--url https://api.fluid.app/api/authentication/confirm_mfa \
--header 'Content-Type: application/json' \
--data '
{
"uuid": "mfa_9f8c1b2a3d4e5f60",
"multi_factor_authentication": {
"verification_code": "123456"
}
}
'import requests
url = "https://api.fluid.app/api/authentication/confirm_mfa"
payload = {
"uuid": "mfa_9f8c1b2a3d4e5f60",
"multi_factor_authentication": { "verification_code": "123456" }
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
uuid: 'mfa_9f8c1b2a3d4e5f60',
multi_factor_authentication: {verification_code: '123456'}
})
};
fetch('https://api.fluid.app/api/authentication/confirm_mfa', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fluid.app/api/authentication/confirm_mfa",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'uuid' => 'mfa_9f8c1b2a3d4e5f60',
'multi_factor_authentication' => [
'verification_code' => '123456'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.fluid.app/api/authentication/confirm_mfa"
payload := strings.NewReader("{\n \"uuid\": \"mfa_9f8c1b2a3d4e5f60\",\n \"multi_factor_authentication\": {\n \"verification_code\": \"123456\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fluid.app/api/authentication/confirm_mfa")
.header("Content-Type", "application/json")
.body("{\n \"uuid\": \"mfa_9f8c1b2a3d4e5f60\",\n \"multi_factor_authentication\": {\n \"verification_code\": \"123456\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fluid.app/api/authentication/confirm_mfa")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"uuid\": \"mfa_9f8c1b2a3d4e5f60\",\n \"multi_factor_authentication\": {\n \"verification_code\": \"123456\"\n }\n}"
response = http.request(request)
puts response.read_body{
"authenticated": true,
"companies": [
{
"id": 123,
"name": "<string>",
"jwt": "<string>",
"shop_name": "<string>",
"logo_url": "<string>",
"primary_domain_hostname": "<string>"
}
],
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error_message": "<string>",
"errors": "<string>",
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error_message": "<string>",
"errors": "<string>",
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error_message": "<string>",
"errors": "<string>",
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}