Two-Factor Authentication
The authenticated user can manage TOTP two-factor authentication through the GraphQL API. These operations are used by profile security settings on mobile.
| Operation | Purpose |
|---|---|
currentUser.twoFactorEnabled | Reports whether TOTP is enabled |
twoFactorRecoveryCodesRemaining | Reports the number of unused recovery codes |
generateTwoFactorSetup | Returns a shared key and authenticator URI |
enableTwoFactor | Verifies the password and TOTP code, enables TOTP, and returns recovery codes |
disableTwoFactor | Verifies a TOTP code and disables TOTP |
regenerateTwoFactorRecoveryCodes | Verifies a TOTP code and replaces the recovery-code set |
query TwoFactorStatus {
currentUser {
twoFactorEnabled
}
twoFactorRecoveryCodesRemaining
}
mutation EnableTwoFactor($input: EnableTwoFactorInput!) {
enableTwoFactor(input: $input) {
recoveryCodes
}
}
EnableTwoFactorInput contains password and code. Disable and recovery-code regeneration inputs contain code. Do not log mutation variables: the enable input contains the user's password. Do not automatically retry these mutations, because replaying an invalid TOTP value can count as another failed attempt. Fetch status from the network rather than a persisted cache, and present returned recovery codes once so the user can store them securely.