Verify MFA Code
This request submits an MFA code to activate a token that was issued with a pending_mfa status. On success, the token's status changes to active and it can be used like any other OAuth token.
| post | /oauth/token/mfa |
Sample
A sample POST request to verify an MFA code, authenticated with the pending token itself:
curl -X POST \
'https://api.carrierx.com/core/v2/oauth/token/mfa' \
-H 'Content-Type: application/json' \
--data-binary '{"code":"847291"}' \
-H 'Authorization: Bearer 8bfd6c6d-6291-488a-bed1-8784c195ce87'
Response
200 status code with a serialized copy of the OAuth Token object, now active:
{
"access_token": "8bfd6c6d-6291-488a-bed1-8784c195ce87",
"client_id": "5c7965f285344165b003ce1a3202e589",
"date_created": "2024-09-11T13:46:42.211Z",
"date_expiration_access_token": "2124-08-18T13:46:42.169Z",
"date_expiration_refresh_token": "2124-08-18T13:46:42.169Z",
"date_last_accessed": "2024-09-11T13:48:19.029Z",
"ip_last_accessed": null,
"name": "N/A",
"partner_login_sid": "7d2a7af0-1b61-48d9-9fc8-35149e42836a",
"partner_sid": "cee93bf3-5746-43fe-a1a2-822c05fef687",
"refresh_token": "ed07dcd6-dfc5-4d7b-b7b4-891441371b3e",
"scopes": [
"partners.read"
],
"status": "active",
"token_sid": "b3f45e4d-7d46-467b-9724-272f57ac420e",
"token_type": "bearer"
}
The access_token value does not change between the pending_mfa and active states — use the same token returned by the original login request for all subsequent calls.
Required Scopes
No partner scope is required for this request. A pending_mfa token automatically carries the authority to call this endpoint, and this endpoint only — it cannot be used for anything else. Authenticate with the pending_mfa token itself, passed as the Bearer credential.
Body Arguments
| Parameter | Data Type | Description |
|---|---|---|
| code required | string | The verification code. For the |
Notes
- A code sent for the
emailorsmsmethod expires 5 minutes after the token was created. An expired code is rejected; the client must re-authenticate via Generate OAuth Bearer Token to receive a new one. - A
totpcode is validated against a 30-second window, with a tolerance of one step (±30 seconds) for clock drift. - Submitting a request with a missing or incorrect
codereturns a400error. Submitting a request with a token that is not inpending_mfastatus (missing, expired, or alreadyactive) returns a401or403error.