Skip to main content

Refresh MFA proof for step-up-protected operations

POST 

/auth/step-up

Verifies a live TOTP or single-use recovery code and stamps User.lastMfaAt. Sub-30-min sessions can then execute high-value routes (payment approve, role assign, claim disburse) without re-prompting.

Request

Responses

Fresh MFA timestamp; caller can retry the step-up-gated request.