- Listing enrolled authenticators
- Enrolling new authenticators (OTP, SMS, Voice, Push, Email)
- Initiating MFA challenges
- Verifying MFA challenges
Methods
challenge()
Parameters
ChallengeAuthenticatorParams
required
Challenge parameters including mfaTokenType: ChallengeAuthenticatorParams
Returns
Promise<ChallengeResponse>
Challenge response with oobCode if applicable
enroll()
Parameters
EnrollParams
required
Enrollment parameters including mfaToken and factorTypeType: EnrollParams
Returns
Promise<EnrollmentResponse>
Enrollment response with authenticator details
getAuthenticators()
Parameters
string
required
MFA token from mfa_required error
Returns
Promise<Authenticator[]>
Array of enrolled authenticators matching the challenge types
getEnrollmentFactors()
Parameters
string
required
MFA token from mfa_required error
Returns
Promise<EnrollmentFactor[]>
Array of enrollment factors available for the user (empty array if no enrollment required)
verify()
Parameters
VerifyParams
required
Verification parameters with OTP, OOB code, or recovery codeType: VerifyParams
Returns
Promise<TokenEndpointResponse>
Token response with access_token, id_token, refresh_token