Skip to main content
POST
Upgrade JWT scope with valid MFA session

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

Body

application/json

email verification response

verificationUUID
string
required
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

verificationToken
string
required

A 6-digit number

Pattern: ^[0-9]{6}$
Example:

"123456"

createMfaToken
object
requestedScopes
enum<string>[]

Optional list of scopes to include in the elevated access token.

Minimum array length: 1

Valid scopes for an elevated access token

Available options:
console:admin_action:review,
console:approval_workflow:update,
console:member:invite,
console:mfa:reset,
console:project:delete,
console:settings:update,
console:sso:update,
console:user:delete,
credential:link,
credential:update,
credential:unlink,
user:update,
user:delete,
wallet:export,
wallet:delete,
wallet:delegate,
wallet:sign,
wallet:restore
Example:

Response

Successful operation

user
object
required
expiresAt
number
required

Format is a unix-based timestamp. When set, this will be the expiration timestamp on the JWT sent using either the jwt field or a response httpOnly cookie set by the server.

Example:

"1715620310"

mfaToken
string

Token used to continue multi-factor authentication flow

jwt
string

Encoded JWT token. This will only be returned when cookie-based authentication is disabled in favor of standard Auth header based authentication.

Example:

"jwt_value"

minifiedJwt
string

Encoded JWT token. This will only be returned when cookie-based authentication is disabled in favor of standard Auth header based authentication.

Example:

"jwt_value"

elevatedAccessToken
string

Encoded JWT token for elevated access. This will only be returned when requestedScopes are requested.

Example:

"jwt_value"

Last modified on January 21, 2026