> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Request a new MFA code for the current challenge

> Invalidates the current challenge and issues a fresh one with the
same loginContext (so the verify step still lands you in the same
branding / institution context). The new challenge has its own 5-min
TTL and its own 5-attempt cap.

**Cooldown:** the previous challenge must be at least 30 seconds old
before a Resend is allowed — prevents email-bombing.

Resend-driven invalidations (where the user never submitted a wrong
code) do NOT count toward the per-account 5-burned-codes-in-1h
lockout cap.




## OpenAPI

````yaml /mdx/api-reference/admin/admin-api.json post /api/auth/mfa-resend
openapi: 3.0.0
info:
  title: Pria Admin API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Admin Memory
    description: Admin inspection and editing of user/instance memory parameters.
  - name: Admin Usage Limits
    description: Per-user usage-vs-cap reporting and account-wide at-limit counts.
paths:
  /api/auth/mfa-resend:
    post:
      tags:
        - Authentication
      summary: Request a new MFA code for the current challenge
      description: |
        Invalidates the current challenge and issues a fresh one with the
        same loginContext (so the verify step still lands you in the same
        branding / institution context). The new challenge has its own 5-min
        TTL and its own 5-attempt cap.

        **Cooldown:** the previous challenge must be at least 30 seconds old
        before a Resend is allowed — prevents email-bombing.

        Resend-driven invalidations (where the user never submitted a wrong
        code) do NOT count toward the per-account 5-burned-codes-in-1h
        lockout cap.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MfaChallengeIdRequest'
      responses:
        '200':
          description: >-
            New code emailed; client must use the newly-returned challengeId for
            subsequent verify / resend / cancel calls.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaResendResponse'
        '400':
          description: Missing challengeId.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
        '410':
          description: Challenge unknown / expired / already verified / cancelled.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
        '429':
          description: >-
            Resend cooldown active — `retryAfter` (seconds) indicates the
            remaining wait.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
        '502':
          description: >-
            Email provider failure — challenge is invalidated; client should
            restart the signin flow.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
components:
  schemas:
    MfaChallengeIdRequest:
      type: object
      required:
        - challengeId
      properties:
        challengeId:
          type: string
          description: Opaque server-issued challenge identifier.
          example: 65f2c9a1d8e4b3c5a1234567
    MfaResendResponse:
      type: object
      properties:
        success:
          type: boolean
          example: true
        challengeId:
          type: string
          description: >-
            Identifier of the freshly-issued challenge. The prior challenge is
            invalidated; future verify / resend / cancel calls must use this new
            id.
          example: 65f2cabe1234e5f6a8765432
        maskedEmail:
          type: string
          example: hu***@praxis-ai.com
    MfaVerifyError:
      type: object
      properties:
        success:
          type: boolean
          example: false
        code:
          type: string
          enum:
            - BAD_REQUEST
            - WRONG_CODE
            - CHALLENGE_EXPIRED
            - TOO_MANY_ATTEMPTS
            - USER_MISSING
            - RESEND_COOLDOWN
            - MFA_NOT_CONFIGURED
            - MFA_EMAIL_FAILED
        message:
          type: string
        attemptsRemaining:
          type: integer
          description: Only present on WRONG_CODE / TOO_MANY_ATTEMPTS responses.
          example: 4
        retryAfter:
          type: integer
          description: >-
            Seconds the client should wait before retrying. Present on
            RESEND_COOLDOWN.
          example: 24

````