Skip to main content

Two-Factor Authentication

The authenticated user can manage TOTP two-factor authentication through the GraphQL API. These operations are used by profile security settings on mobile.

OperationPurpose
currentUser.twoFactorEnabledReports whether TOTP is enabled
twoFactorRecoveryCodesRemainingReports the number of unused recovery codes
generateTwoFactorSetupReturns a shared key and authenticator URI
enableTwoFactorVerifies the password and TOTP code, enables TOTP, and returns recovery codes
disableTwoFactorVerifies a TOTP code and disables TOTP
regenerateTwoFactorRecoveryCodesVerifies a TOTP code and replaces the recovery-code set
query TwoFactorStatus {
currentUser {
twoFactorEnabled
}
twoFactorRecoveryCodesRemaining
}

mutation EnableTwoFactor($input: EnableTwoFactorInput!) {
enableTwoFactor(input: $input) {
recoveryCodes
}
}

EnableTwoFactorInput contains password and code. Disable and recovery-code regeneration inputs contain code. Do not log mutation variables: the enable input contains the user's password. Do not automatically retry these mutations, because replaying an invalid TOTP value can count as another failed attempt. Fetch status from the network rather than a persisted cache, and present returned recovery codes once so the user can store them securely.