You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(graphql-api): remove verify_totp, a mutation that does not exist (#91)
The page documented a `verify_totp` mutation, an input type
`VerifyTOTPRequest`, a `token` param and a `recovery_code` response
field. None of them exist in the schema. TOTP is verified with
verify_otp(is_totp: true), the same mutation used for email and SMS.
Also on the login response table: `totp_base64_url` and `totp_token`
are not AuthResponse fields. The real ones are
authenticator_scanner_image, authenticator_secret and
authenticator_recovery_codes.
verify_otp's own params table was missing is_totp and state.
The {#verify_totp} anchor is kept so existing deep links resolve.
Copy file name to clipboardExpand all lines: docs/core/graphql-api.md
+24-12Lines changed: 24 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -426,7 +426,7 @@ A mutation to login users using email and password. It accepts `params` of type
426
426
Either `email` or `phone_number` is required to login
427
427
428
428
> Note: To enable MFA, go to dashboard and enable MFA for user. By default, TOTP MFA will be enabled. If SMTP details are provided then Mail OTP can also be enabled. One can only enable one MFA at a time.
429
-
> For TOTP verification use `verify_totp` mutation, and for verifying mail OTP use `verify_otp` mutation.
429
+
> Every second factor is verified with the same [`verify_otp`](#verify_otp) mutation — pass `is_totp: true` for an authenticator code, and omit it for an email or SMS code.
430
430
431
431
**Request Params**
432
432
@@ -452,8 +452,9 @@ This mutation returns `AuthResponse` type with following keys
452
452
|`id_token`| JWT token holding the user information |
453
453
|`refresh_token`| When scope includes `offline_access`, Long living token is returned which can be used to get new access tokens. This is rotated with each request |
454
454
|`user`| User object with its profile keys mentioned [above](#profile). |
455
-
|`totp_base64_url`| If totp enabled, will get base64 url for QR code, which can be scanned on google authenticator |
456
-
|`totp_token`| this token is for totp which need to passed in verify_totp mutation along with totp from your authenticator |
455
+
|`authenticator_scanner_image`| If TOTP enrollment is in progress, a base64 QR image that can be scanned with an authenticator app |
456
+
|`authenticator_secret`| The TOTP shared secret, for entering by hand when a QR code cannot be scanned |
457
+
|`authenticator_recovery_codes`| Recovery codes, returned once when TOTP enrollment completes |
457
458
458
459
**Sample Mutation**
459
460
@@ -734,6 +735,8 @@ Mutation to verify OTP sent to the user. It accepts `params` of type `VerifyOTPR
734
735
|`email`| Email address of user | false |
735
736
|`phone_number`| Phone number of user | false |
736
737
|`otp`| OTP (One Time Password) sent to user email address | true |
738
+
|`is_totp`| Set `true` when the code came from an authenticator app rather than email/SMS. Also completes TOTP enrollment after `totp_mfa_setup`| false |
739
+
|`state`| Authorization-code grant flow state, to obtain a `code` for an in-progress `/authorize` request | false |
737
740
738
741
Either `email` or `phone_number` is required
739
742
@@ -922,16 +925,25 @@ Lists the authenticated caller's own registered passkeys. Returns `[WebauthnCred
922
925
923
926
Deletes one of the authenticated caller's own passkeys by `id`. Returns `Response`. Requires authentication.
924
927
925
-
### `verify_totp`
928
+
### Verifying TOTP {#verify_totp}
926
929
927
-
Mutation to verify TOTP generated by QR code. It accepts `params` of type `VerifyTOTPRequest` with following keys as parameter
930
+
There is no separate `verify_totp` mutation. TOTP codes go through
931
+
[`verify_otp`](#verify_otp) with `is_totp: true` — the same mutation that verifies
932
+
email and SMS codes, so one code path handles every second factor.
|`is_totp`| Must be `true` for an authenticator code | true |
942
+
|`state`| Authorization-code grant flow state | false |
943
+
944
+
Either `email` or `phone_number` is required — it identifies which pending login
945
+
this code belongs to. The same call completes enrollment after
946
+
[`totp_mfa_setup`](#totp_mfa_setup).
935
947
936
948
This mutation returns `AuthResponse` type with following keys
937
949
@@ -945,13 +957,13 @@ This mutation returns `AuthResponse` type with following keys
945
957
|`id_token`| JWT token holding the user information |
946
958
|`refresh_token`| When scope includes `offline_access`, Long living token is returned which can be used to get new access tokens. This is rotated with each request |
947
959
|`user`| User object with its profile keys mentioned [above](#profile). |
948
-
|`recovery_code`| One will get a recovery code when signed in first time using TOTP.|
960
+
|`authenticator_recovery_codes`| Recovery codes, returned once when TOTP enrollment completes. |
0 commit comments