2 Factor Authentication

2fa can help massively to improve security on a website. It will slow down an attacker - maybe even stop.

Get 2FA Details

GET https://accountable.pixelninja.dev/:token/user/:uuid/2fa

This will give basic details about a user's 2fa status. This will include when it was enabled and their 2fa token. You can use this endpoint 10 times per second.

Path Parameters

Name
Type
Description

token

string

This is your API token.

uuid

string

This is the UUID of the user from who you are getting details.

{
    "enabled": true,
    "token": "PJOVGYTRLAWEKR22JQVHQI2REM7XQRSSJR5U4JKUEM3UIY2WKJ5Q",
    "enabledAt": 1621412871743
}

Enable 2FA

POST https://accountable.pixelninja.dev/:token/user/:uuid/2fa

Enable 2fa for provided user. It will return a QR code data URI and the 2fa token (Not to be confused with an access token or MFA token) that can be used to calculate the time-based pin. This endpoint can be used 2 times per second.

Path Parameters

Name
Type
Description

token

string

This is your API token.

uuid

string

The UUID of the user who is having 2fa enabled.

Request Body

Name
Type
Description

issuer

string

This is the name that will show in the user's 2FA app.

{
    "token": "PJOVGYTRLAWEKR22JQVHQI2REM7XQRSSJR5U4JKUEM3UIY2WKJ5Q",
    "qrcode": ""
}

"issuer" will default to "Accountable" if not set.

Remove 2FA

DELETE https://accountable.pixelninja.dev/:token/user/:uuid/2fa

Remove 2fa for the specified user. It will delete the stored 2fa token and set enabled to false. This endpoint can be used 3 times per second.

Path Parameters

Name
Type
Description

token

string

This is your API token

uuid

string

The UUID of the user whose 2FA you are disabling.

{ "code": 204, "message": "No content" }

Authenticating With 2FA

What is 2FA if you can't actually use it to login? This section will cover how to check a user's 2FA PIN and managing the 2FA sign-in process.

Authenticate 2FA PIN

POST https://accountable.pixelninja.dev/:token/users/authenticate/2fa

This endpoint takes an MFA token (which should have been assigned at login) and a 6 digit pin provided by the user. It will return telling you if the details match!

Path Parameters

Name
Type
Description

token

string

This is your API token.

Request Body

Name
Type
Description

token

string

This is the MFA token of the user who is authenticating.

code

string

This is the 6 digit code they entered.

{ 
    "uuid": "d4b4e3d7-c081-4937-ae96-0ec140111f5b", 
    "accessToken": "ZDRiNGUzZDctYzA4MS00OTM3LWFlOTYtMGVjMTQwMTExZjVi.MTYyMTQxMjU3MTYyNg.xcvZeUyucHoj7TwWqZiTm4w8IpZsOWlz", 
    "code": 200 
}

Last updated

Was this helpful?