OUTCOME · Create or advance
What changes
Consumes the pending enrollment, enables TOTP, and returns ten single-use recovery codes once.
v2Authentication
/api/v2/me/authenticator-enrollments/{enrollment_id}/confirmationsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Confirm immediately after enrollment with a current six-digit TOTP generated from the returned secret in the same account session.
OUTCOME · Create or advance
Consumes the pending enrollment, enables TOTP, and returns ten single-use recovery codes once.
WHY IT MATTERS
ISOLATION + AUTHORITY
Tenant identity, profile, password, authenticator enrollment, recovery code, device, session, access token, refresh credential, step-up grant, and account-closure state remain distinct. Authentication proves only the admitted session and scopes; it grants no workspace role, wallet, payment, settlement, publisher, matching, or trading authority.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the security:write scope.EXAMPLEBearer hc_live_…
Idempotency-KeyheaderRequiredASCII string · 1–128Caller-generated key reused for every retry of the same logical mutation.EXAMPLElaunch-treasury-v1-001
Content-TypeheaderRequiredapplication/jsonSigned mutations accept canonical JSON only.EXAMPLEapplication/json
Content-DigestheaderRequiredRFC 9530 SHA-256 digestDigest of the exact transmitted body bytes.EXAMPLEsha-256=:47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=:
Signature-InputheaderRequiredRFC 9421 signature parametersCovers @method, @path, content-digest, content-type, and idempotency-key; includes keyid, nonce, created, and expires.EXAMPLEsig1=("@method" "@path" "content-digest" "content-type" "idempotency-key");created=1786582800;expires=1786583100;nonce="01J…";keyid="machine-prod"
SignatureheaderRequiredEd25519 HTTP Message SignatureSignature made by an active public key registered to the authenticated client.EXAMPLEsig1=:base64-signature:
enrollment_idpathRequired32-character identifierPending enrollment returned by the begin call and bound to this session.
codebodyRequired6-digit TOTPCurrent code generated from the pending enrollment secret.
REQUEST
{
"code": "123456"
}STABLE ERROR CODES
These codes are published by the authoritative gateway contract for this endpoint. Treat message as safe diagnostic text; integrations should branch on code and HTTP status.
invalid_jsonThe JSON body is malformed or fails the published identity-security schema.invalid_security_requestThe session, scope, public key, proof, or purpose-bound security request is invalid.invalid_credentialsThe bearer, client assertion, or proof-of-possession credential is invalid.step_up_requiredFresh purpose-bound authenticator verification or stronger authority is required.signing_key_not_foundThe requested signing-key or workload-client resource was not found.security_conflictThe requested identity-security transition conflicts with current state.identity_security_unavailableThe authoritative Identity security service is temporarily unavailable.RESPONSES
{
"status": "ENABLED",
"recovery_codes": [
"A1B2C3D4E5-F6A7B8C9D0",
"… nine more …"
],
"warning": "Store these recovery codes now; they will not be shown again."
}{
"code": "invalid_security_request",
"message": "The enrollment identifier or code shape is invalid."
}invalid_security_request{
"code": "invalid_credentials",
"message": "The bearer credential is invalid."
}invalid_credentials{
"code": "step_up_required",
"message": "The enrollment is expired, cross-session, already consumed, or the code is invalid."
}step_up_required{
"code": "identity_security_unavailable",
"message": "Identity or authenticator encryption is unavailable."
}identity_security_unavailableOPERATIONAL NOTES
UPGRADING FROM V1
If you maintain an older integration, use this map to find the V2 replacement. Do not translate the old request field-for-field: rebuild it from the V2 parameters and schemas above because identity, authorization, replay protection, and response semantics may have changed.
/api/v1/auth/submitfirst2facodeAUTH: Submit first 2FA CodeThis route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗