Add Multi-Factor (MFA)
Add a multi-factor (MFA) to the login settings of the instance. It affects all organizations, without custom login settings. Authentication factors are used as an additional layer of security for your users (e.g. Authentication App, FingerPrint, Windows Hello, etc). Per definition, it is called multi-factor factor or passwordless as it is used as first and second authentication and a password is not necessary. In the UI we generalize it as passwordless or passkey.
Request Body required
Possible values: [MULTI_FACTOR_TYPE_UNSPECIFIED
, MULTI_FACTOR_TYPE_U2F_WITH_VERIFICATION
]
Default value: MULTI_FACTOR_TYPE_UNSPECIFIED
Request Body required
Possible values: [MULTI_FACTOR_TYPE_UNSPECIFIED
, MULTI_FACTOR_TYPE_U2F_WITH_VERIFICATION
]
Default value: MULTI_FACTOR_TYPE_UNSPECIFIED
Request Body required
Possible values: [MULTI_FACTOR_TYPE_UNSPECIFIED
, MULTI_FACTOR_TYPE_U2F_WITH_VERIFICATION
]
Default value: MULTI_FACTOR_TYPE_UNSPECIFIED
- 200
- 400
- 403
- 404
- default
multi-factor added to default login policy
Schema
details object
{
"details": {
"sequence": "2",
"creationDate": "2024-01-15T17:30:59.783Z",
"changeDate": "2024-01-15T17:30:59.783Z",
"resourceOwner": "69629023906488334"
}
}
Schema
details object
{
"details": {
"sequence": "2",
"creationDate": "2024-01-15T17:30:59.784Z",
"changeDate": "2024-01-15T17:30:59.784Z",
"resourceOwner": "69629023906488334"
}
}
Schema
details object
{
"details": {
"sequence": "2",
"creationDate": "2024-01-15T17:30:59.784Z",
"changeDate": "2024-01-15T17:30:59.784Z",
"resourceOwner": "69629023906488334"
}
}
invalid multi-factor type
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Returned when the user does not have permission to access the resource.
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Returned when the resource does not exist.
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
An unexpected error response.
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
Schema
details object[]
{
"code": 0,
"message": "string",
"details": [
{
"@type": "string"
}
]
}
POST /policies/login/multi_factors
Authorization
name: OAuth2type: oauth2scopes:openid,urn:zitadel:iam:org:project:id:zitadel:aud
flows: { "authorizationCode": { "authorizationUrl": "$CUSTOM-DOMAIN/oauth/v2/authorize", "tokenUrl": "$CUSTOM-DOMAIN/oauth/v2/token", "scopes": { "openid": "openid", "urn:zitadel:iam:org:project:id:zitadel:aud": "urn:zitadel:iam:org:project:id:zitadel:aud" } } }
Request
Request
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'
curl -L -X POST 'https://$CUSTOM-DOMAIN/admin/v1/policies/login/multi_factors' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
--data-raw '{
"type": "MULTI_FACTOR_TYPE_UNSPECIFIED"
}'