Use this API to authenticate a one-time password (OTP) code provided by a multifactor authentication (MFA) device.
Use this endpoint to verify an OTP code provided by SMS, Email, or Authenticator. The verification_id parameter required by the PUT verification method is not required when the HTTP method is POST.
Resource URL
https://<subdomain>.onelogin.com/api/2/mfa/users/<user_id>/verifications/Header Parameter
Authorization required string | Set to Set The access token must have been generated using an API credential pair created using the scope required to call this API. This API can be called using the |
Resource Parameters
user_id required integer | Set to the If you don't know the user's |
Request Parameter
otp string | OTP code provided by the device or SMS message sent to user. |
device_id integer | ID of the specified device which has been registerd for the given user. Available on Get Devices API call. |
Request Body
For OneLogin Email and OneLogin SMS:
{
"otp": "123456"
}
```xml
<p>For Authenticator OTP: </p>
```json
{
"otp": "123456",
"device_id": "98765"
}
```xml
<h2>Sample Response</h2>
<div class="code-tabs">
<ul class="tab-links" role="tablist">
<li class="t-link active" data-tab="1" role="tab" aria-selected="true" tabindex="0">200 OK</li>
<li class="t-link" data-tab="2" role="tab" aria-selected="false" tabindex="0">401 Unauthorized</li>
<li class="t-link" data-tab="3" role="tab" aria-selected="false" tabindex="0">403 Forbidden</li>
</ul>
<div class="tab-views">
```json
{
"status": {
"type": "success",
"code": 200,
"message": "Success",
"error": false
}
}{
"statusCode": 401,
"name": "InvalidCredentials",
"message": "Please provide valid credentials"
}{
"statusCode": 403,
"name": "ForbiddenAction",
"message": "You are not authorised to perform this action or access the resource"
}
```json
</div>
</div>
<h2 id="postman-collection">Postman Collection</h2>
[<img src=https://run.pstmn.io/button.svg alt="Run In Postman" style="width: 128px; height: 32px;">](https://god.gw.postman.com/run-collection/2629710-07192ad9-633a-4583-a9d1-47bc89c8c91d?action=collection%2Ffork&source=rip_markdown&collection-url=entityId%3D2629710-07192ad9-633a-4583-a9d1-47bc89c8c91d%26entityType%3Dcollection%26workspaceId%3D2a9bbc3a-4259-4faf-9f51-0b7ca1df3fd0)
<h2>Sample Code</h2>
<h3 id="sample-curl-request">cURL</h3>
<p>Replace sample values indicated by <code>< ></code> with your actual values.</p>
<pre><code class="prettyprint lang-c">curl 'https://<subdomain>.onelogin.com/api/2/mfa/users/<user_id>/verifications/' \
-X POST \
-H "Authorization: bearer <access_token>" \
-H "Content-Type: application/json" \
-d '{
"otp":"123456"
}'</code>
</pre>Have a Question?
Found a problem or a bug? Submit a support ticket.
Looking for walkthroughs or how-to guides? Check out our Knowledge Base.
Have a product idea or request? Share it in our Ideas Portal.