> This page is for Developers.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.emnify.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.emnify.com/_mcp/server.

> Handle multi-factor authentication (MFA) when authenticating with user credentials, including the two-step verification flow and trusted device management.

When multi-factor authentication (MFA) is enabled for your account, you must complete a two-step verification process to authenticate.

> **Tip**
>
> MFA applies only when authenticating with [user credentials](/developers/auth/user-credentials).
> Use [application tokens](/developers/auth/application-tokens) instead.
> They don't require MFA handling and are the recommended authentication method for all API integrations.

## Two-step authentication flow

### Submit credentials and receive MFA token

Send your username and SHA-1 hashed password to `/api/v1/authenticate`.
Instead of the usual `auth_token`, the server returns an `mfa_token` and sends a one-time password (OTP) to your registered email or authenticator app.

### Request

POST [https://cdn.emnify.net/api/v1/authenticate](https://cdn.emnify.net/api/v1/authenticate)

**`User Authentication with MFA Enabled - Receive MFA Token`**

```curl User Authentication with MFA Enabled - Receive MFA Token
curl -X POST https://cdn.emnify.net/api/v1/authenticate \
     -H "Content-Type: application/json" \
     -d '{
  "username": "user@service.org",
  "password": "8Y8knYSkeyYV23kd"
}'
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```python User Authentication with MFA Enabled - Receive MFA Token
import requests

url = "https://cdn.emnify.net/api/v1/authenticate"

payload = {
    "username": "user@service.org",
    "password": "8Y8knYSkeyYV23kd"
}
headers = {"Content-Type": "application/json"}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```javascript User Authentication with MFA Enabled - Receive MFA Token
const url = 'https://cdn.emnify.net/api/v1/authenticate';
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/json'},
  body: '{"username":"user@service.org","password":"8Y8knYSkeyYV23kd"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```go User Authentication with MFA Enabled - Receive MFA Token
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://cdn.emnify.net/api/v1/authenticate"

	payload := strings.NewReader("{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```ruby User Authentication with MFA Enabled - Receive MFA Token
require 'uri'
require 'net/http'

url = URI("https://cdn.emnify.net/api/v1/authenticate")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\"\n}"

response = http.request(request)
puts response.read_body
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```java User Authentication with MFA Enabled - Receive MFA Token
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://cdn.emnify.net/api/v1/authenticate")
  .header("Content-Type", "application/json")
  .body("{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\"\n}")
  .asString();
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```php User Authentication with MFA Enabled - Receive MFA Token
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://cdn.emnify.net/api/v1/authenticate', [
  'body' => '{
  "username": "user@service.org",
  "password": "8Y8knYSkeyYV23kd"
}',
  'headers' => [
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```csharp User Authentication with MFA Enabled - Receive MFA Token
using RestSharp;

var client = new RestClient("https://cdn.emnify.net/api/v1/authenticate");
var request = new RestRequest(Method.POST);
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`User Authentication with MFA Enabled - Receive MFA Token`**

```swift User Authentication with MFA Enabled - Receive MFA Token
import Foundation

let headers = ["Content-Type": "application/json"]
let parameters = [
  "username": "user@service.org",
  "password": "8Y8knYSkeyYV23kd"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://cdn.emnify.net/api/v1/authenticate")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Response (200)

```json
{
  "mfa_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
```

### Verify OTP and receive auth token

Send the `mfa_token` from Step 1 along with the 6-digit OTP `code` to `/api/v1/authenticate`.
If verification succeeds, the server returns your `auth_token` and `refresh_token`.

### Request

POST [https://cdn.emnify.net/api/v1/authenticate](https://cdn.emnify.net/api/v1/authenticate)

**`MFA Code Verification - Trust Device for 90 Days`**

```curl MFA Code Verification - Trust Device for 90 Days
curl -X POST https://cdn.emnify.net/api/v1/authenticate \
     -H "Content-Type: application/json" \
     -d '{
  "mfa_token": "zI1NiIsInR5cCI6IkpXV...",
  "code": "123456",
  "trusted_device": {
    "fingerprint": "zI1NiIsInR5cCI6IkpXV",
    "operating_system": "Ubuntu 16.04.2 LTS (Xenial)",
    "browser": "Mozilla Firefox"
  }
}'
```

**`MFA Code Verification - Trust Device for 90 Days`**

```python MFA Code Verification - Trust Device for 90 Days
import requests

url = "https://cdn.emnify.net/api/v1/authenticate"

payload = {
    "mfa_token": "zI1NiIsInR5cCI6IkpXV...",
    "code": "123456",
    "trusted_device": {
        "fingerprint": "zI1NiIsInR5cCI6IkpXV",
        "operating_system": "Ubuntu 16.04.2 LTS (Xenial)",
        "browser": "Mozilla Firefox"
    }
}
headers = {"Content-Type": "application/json"}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

**`MFA Code Verification - Trust Device for 90 Days`**

```javascript MFA Code Verification - Trust Device for 90 Days
const url = 'https://cdn.emnify.net/api/v1/authenticate';
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/json'},
  body: '{"mfa_token":"zI1NiIsInR5cCI6IkpXV...","code":"123456","trusted_device":{"fingerprint":"zI1NiIsInR5cCI6IkpXV","operating_system":"Ubuntu 16.04.2 LTS (Xenial)","browser":"Mozilla Firefox"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`MFA Code Verification - Trust Device for 90 Days`**

```go MFA Code Verification - Trust Device for 90 Days
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://cdn.emnify.net/api/v1/authenticate"

	payload := strings.NewReader("{\n  \"mfa_token\": \"zI1NiIsInR5cCI6IkpXV...\",\n  \"code\": \"123456\",\n  \"trusted_device\": {\n    \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\",\n    \"operating_system\": \"Ubuntu 16.04.2 LTS (Xenial)\",\n    \"browser\": \"Mozilla Firefox\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`MFA Code Verification - Trust Device for 90 Days`**

```ruby MFA Code Verification - Trust Device for 90 Days
require 'uri'
require 'net/http'

url = URI("https://cdn.emnify.net/api/v1/authenticate")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n  \"mfa_token\": \"zI1NiIsInR5cCI6IkpXV...\",\n  \"code\": \"123456\",\n  \"trusted_device\": {\n    \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\",\n    \"operating_system\": \"Ubuntu 16.04.2 LTS (Xenial)\",\n    \"browser\": \"Mozilla Firefox\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

**`MFA Code Verification - Trust Device for 90 Days`**

```java MFA Code Verification - Trust Device for 90 Days
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://cdn.emnify.net/api/v1/authenticate")
  .header("Content-Type", "application/json")
  .body("{\n  \"mfa_token\": \"zI1NiIsInR5cCI6IkpXV...\",\n  \"code\": \"123456\",\n  \"trusted_device\": {\n    \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\",\n    \"operating_system\": \"Ubuntu 16.04.2 LTS (Xenial)\",\n    \"browser\": \"Mozilla Firefox\"\n  }\n}")
  .asString();
```

**`MFA Code Verification - Trust Device for 90 Days`**

```php MFA Code Verification - Trust Device for 90 Days
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://cdn.emnify.net/api/v1/authenticate', [
  'body' => '{
  "mfa_token": "zI1NiIsInR5cCI6IkpXV...",
  "code": "123456",
  "trusted_device": {
    "fingerprint": "zI1NiIsInR5cCI6IkpXV",
    "operating_system": "Ubuntu 16.04.2 LTS (Xenial)",
    "browser": "Mozilla Firefox"
  }
}',
  'headers' => [
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

**`MFA Code Verification - Trust Device for 90 Days`**

```csharp MFA Code Verification - Trust Device for 90 Days
using RestSharp;

var client = new RestClient("https://cdn.emnify.net/api/v1/authenticate");
var request = new RestRequest(Method.POST);
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"mfa_token\": \"zI1NiIsInR5cCI6IkpXV...\",\n  \"code\": \"123456\",\n  \"trusted_device\": {\n    \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\",\n    \"operating_system\": \"Ubuntu 16.04.2 LTS (Xenial)\",\n    \"browser\": \"Mozilla Firefox\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`MFA Code Verification - Trust Device for 90 Days`**

```swift MFA Code Verification - Trust Device for 90 Days
import Foundation

let headers = ["Content-Type": "application/json"]
let parameters = [
  "mfa_token": "zI1NiIsInR5cCI6IkpXV...",
  "code": "123456",
  "trusted_device": [
    "fingerprint": "zI1NiIsInR5cCI6IkpXV",
    "operating_system": "Ubuntu 16.04.2 LTS (Xenial)",
    "browser": "Mozilla Firefox"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://cdn.emnify.net/api/v1/authenticate")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Response (200)

```json
{
  "auth_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
```

## Skip MFA with trusted devices

To avoid entering an OTP code on every login, you can register your device as trusted.
Trusted devices skip the MFA verification step for 90 days.

### Register a trusted device

Include the `trusted_device` object in your Step 2 request:

| Field              | Required | Description                                          |
| ------------------ | :------: | ---------------------------------------------------- |
| `fingerprint`      |    Yes   | Unique identifier for the device (you generate this) |
| `operating_system` |    No    | Device OS (for your reference)                       |
| `browser`          |    No    | Browser name (for your reference)                    |
| `name`             |    No    | Friendly name for the device                         |

> **Note**
>
> The `fingerprint` must be unique and consistent for each device.
> You're responsible for generating and storing this identifier in your application.

### Authenticate with a trusted device

Once registered, include the `fingerprint` in your initial authentication request.
If the fingerprint matches a trusted device, the server returns `auth_token` and `refresh_token` immediately, skipping the OTP step.

### Request

POST [https://cdn.emnify.net/api/v1/authenticate](https://cdn.emnify.net/api/v1/authenticate)

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```curl User Authentication with Trusted Device Fingerprint - Skip MFA
curl -X POST https://cdn.emnify.net/api/v1/authenticate \
     -H "Content-Type: application/json" \
     -d '{
  "username": "user@service.org",
  "password": "8Y8knYSkeyYV23kd",
  "fingerprint": "zI1NiIsInR5cCI6IkpXV"
}'
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```python User Authentication with Trusted Device Fingerprint - Skip MFA
import requests

url = "https://cdn.emnify.net/api/v1/authenticate"

payload = {
    "username": "user@service.org",
    "password": "8Y8knYSkeyYV23kd",
    "fingerprint": "zI1NiIsInR5cCI6IkpXV"
}
headers = {"Content-Type": "application/json"}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```javascript User Authentication with Trusted Device Fingerprint - Skip MFA
const url = 'https://cdn.emnify.net/api/v1/authenticate';
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/json'},
  body: '{"username":"user@service.org","password":"8Y8knYSkeyYV23kd","fingerprint":"zI1NiIsInR5cCI6IkpXV"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```go User Authentication with Trusted Device Fingerprint - Skip MFA
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://cdn.emnify.net/api/v1/authenticate"

	payload := strings.NewReader("{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\",\n  \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```ruby User Authentication with Trusted Device Fingerprint - Skip MFA
require 'uri'
require 'net/http'

url = URI("https://cdn.emnify.net/api/v1/authenticate")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\",\n  \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\"\n}"

response = http.request(request)
puts response.read_body
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```java User Authentication with Trusted Device Fingerprint - Skip MFA
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://cdn.emnify.net/api/v1/authenticate")
  .header("Content-Type", "application/json")
  .body("{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\",\n  \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\"\n}")
  .asString();
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```php User Authentication with Trusted Device Fingerprint - Skip MFA
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://cdn.emnify.net/api/v1/authenticate', [
  'body' => '{
  "username": "user@service.org",
  "password": "8Y8knYSkeyYV23kd",
  "fingerprint": "zI1NiIsInR5cCI6IkpXV"
}',
  'headers' => [
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```csharp User Authentication with Trusted Device Fingerprint - Skip MFA
using RestSharp;

var client = new RestClient("https://cdn.emnify.net/api/v1/authenticate");
var request = new RestRequest(Method.POST);
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"username\": \"user@service.org\",\n  \"password\": \"8Y8knYSkeyYV23kd\",\n  \"fingerprint\": \"zI1NiIsInR5cCI6IkpXV\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`User Authentication with Trusted Device Fingerprint - Skip MFA`**

```swift User Authentication with Trusted Device Fingerprint - Skip MFA
import Foundation

let headers = ["Content-Type": "application/json"]
let parameters = [
  "username": "user@service.org",
  "password": "8Y8knYSkeyYV23kd",
  "fingerprint": "zI1NiIsInR5cCI6IkpXV"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://cdn.emnify.net/api/v1/authenticate")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Response (200)

```json
{
  "auth_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
```

## MFA key object

The following table describes the properties of the **MFA key** object.

| Property          | Type      | Description                                                                          |
| :---------------- | :-------- | :----------------------------------------------------------------------------------- |
| `id`              | Integer   | Unique identifier of this MFA key                                                    |
| `status`          | Object    | Information about the MFA key status (see [Status object](#status-object))           |
| `type`            | Object    | Information about the MFA key type (see [Type object](#type-object))                 |
| `secret_key`      | String    | A Base32 encoded secret key for this MFA key  *Note: This only displays on creation* |
| `otpauth`         | String    | The secret key, but URI-encoded for QR codes  *Note: This only displays on creation* |
| `creation_date`   | Timestamp | Date/time when this MFA key was created  *Type: ISO 8601 timestamp format*           |
| `activation_date` | Timestamp | Date/time when this MFA key was activated  *Type: ISO 8601 timestamp format*         |

### Status object

| Property      | Type    | Description               |
| :------------ | :------ | :------------------------ |
| `id`          | Integer | Status ID of this MFA key |
| `description` | String  | Description of the status |

### Type object

| Property      | Type    | Description             |
| :------------ | :------ | :---------------------- |
| `id`          | Integer | Type ID of this MFA key |
| `description` | String  | Description of the type |

## Manage MFA keys

Use the following endpoints to manage MFA keys and trusted devices:

| Endpoint                                                                                                        | Description                             |
| --------------------------------------------------------------------------------------------------------------- | --------------------------------------- |
| [Create MFA key](/developers/api/authentication/post-mfa)                                                       | Create a new MFA key for a user         |
| [Activate MFA key](/developers/api/authentication/user-mfa-by-id-patch)                                         | Activate an MFA key with a 6-digit code |
| [Delete MFA key](/developers/api/authentication/user-mfa-by-user-id-and-key-id-delete)                          | Delete an existing MFA key              |
| [Get MFA status](/developers/api/authentication/user-mfa-status-get)                                            | Retrieve available MFA statuses         |
| [Get MFA types](/developers/api/authentication/user-mfa-type-get)                                               | Retrieve available MFA types            |
| [List trusted devices](/developers/api/authentication/user-mfa-trusted-device-by-user-id-get)                   | Get all trusted devices for a user      |
| [Delete trusted device](/developers/api/authentication/user-mfa-trusted-device-by-user-id-and-device-id-delete) | Remove a trusted device                 |

## Errors

The following table lists errors that may occur during MFA operations.

| Error            | Code | Cause                          |
| ---------------- | :--: | ------------------------------ |
| 401 Unauthorized |   -  | Password is invalid            |
| 409 Duplicated   | 1405 | MFA key already exists         |
| 422 InvalidValue | 1400 | MFA key type is invalid        |
| 422 Required     | 1400 | Password or type field missing |

### Solutions

* **401 Unauthorized**: Verify your password is correctly [SHA-1 hashed](/developers/auth/user-credentials#hash-your-password-with-sha-1) before sending.
  Use the `-n` flag with `echo` to avoid trailing newlines.
* **409 Duplicated**: [Delete the existing MFA key](/developers/api/authentication/user-mfa-by-user-id-and-key-id-delete) before creating a new one.
* **422 InvalidValue**: [Get the available MFA types](/developers/api/authentication/user-mfa-type-get) to find valid type IDs.
* **422 Required**: Include both `type` (with `id`) and `password` fields in your request body.