Complete an MFA login challenge. Returns the issued session.
Complete an MFA login challenge. Returns the issued session.
POST
https://app.softsolz.uk/api/v1/services/customer-auth/sessions/mfaRecent Requests
Kept only in this browserTimeStatusTook
Send a request with Try it to see it here.
Headers
AuthorizationstringrequiredBearer token: `Bearer sk_live_...` (or `sk_test_...` for sandbox). A login token will not work here.
Body Params
challenge_tokenstringrequiredThe challenge_token from the MFA branch of POST /sessions.
codestringrequiredA 6-digit TOTP code or a 19-char recovery code.
Response
Response Body
userobjectEnd-user identity.sessionobjectThe issued session token and its metadata.Request
curl --request POST \ --url https://app.softsolz.uk/api/v1/services/customer-auth/sessions/mfa \ --header 'Authorization: Bearer sk_live_your_key' \ --header 'Content-Type: application/json' \ --data '{ "challenge_token": "tok_example", "code": "123456"}'Credentials
Sent as a Bearer token and used in the samples above and in Try it. Kept only in this browser tab until you close it. Use an sk_test_ key to stay in your sandbox.
Response · 200
{ "data": { "user": { "id": "1042", "email": "user@example.com" }, "session": { "token": "tok_example", "jti": "11111111-1111-1111-1111-111111111111", "issued_at": "2026-02-01T12:00:00.000Z", "expires_at": "2026-02-08T12:00:00.000Z" } }}