Skip to main content

Verify MFA Code

This request submits an MFA code to activate a token that was issued with a pending_mfa status. On success, the token's status changes to active and it can be used like any other OAuth token.

post /oauth/token/mfa

Sample​

A sample POST request to verify an MFA code, authenticated with the pending token itself:

curl -X POST \
'https://api.carrierx.com/core/v2/oauth/token/mfa' \
-H 'Content-Type: application/json' \
--data-binary '{"code":"847291"}' \
-H 'Authorization: Bearer 8bfd6c6d-6291-488a-bed1-8784c195ce87'

Response​

200 status code with a serialized copy of the OAuth Token object, now active:

{
"access_token": "8bfd6c6d-6291-488a-bed1-8784c195ce87",
"client_id": "5c7965f285344165b003ce1a3202e589",
"date_created": "2024-09-11T13:46:42.211Z",
"date_expiration_access_token": "2124-08-18T13:46:42.169Z",
"date_expiration_refresh_token": "2124-08-18T13:46:42.169Z",
"date_last_accessed": "2024-09-11T13:48:19.029Z",
"ip_last_accessed": null,
"name": "N/A",
"partner_login_sid": "7d2a7af0-1b61-48d9-9fc8-35149e42836a",
"partner_sid": "cee93bf3-5746-43fe-a1a2-822c05fef687",
"refresh_token": "ed07dcd6-dfc5-4d7b-b7b4-891441371b3e",
"scopes": [
"partners.read"
],
"status": "active",
"token_sid": "b3f45e4d-7d46-467b-9724-272f57ac420e",
"token_type": "bearer"
}

The access_token value does not change between the pending_mfa and active states — use the same token returned by the original login request for all subsequent calls.

Required Scopes​

No partner scope is required for this request. A pending_mfa token automatically carries the authority to call this endpoint, and this endpoint only — it cannot be used for anything else. Authenticate with the pending_mfa token itself, passed as the Bearer credential.

Body Arguments​

ParameterData TypeDescription
code
required
string

The verification code. For the email and sms methods, this is the code sent to the login's configured email or phonenumber. For the totp method, this is the current code generated by the login's authenticator app.

Notes​

  • A code sent for the email or sms method expires 5 minutes after the token was created. An expired code is rejected; the client must re-authenticate via Generate OAuth Bearer Token to receive a new one.
  • A totp code is validated against a 30-second window, with a tolerance of one step (±30 seconds) for clock drift.
  • Submitting a request with a missing or incorrect code returns a 400 error. Submitting a request with a token that is not in pending_mfa status (missing, expired, or already active) returns a 401 or 403 error.