> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit a 6-digit MFA code to complete login

> Second leg of the MFA login flow. The first leg (POST /api/auth/signin
or /autosignup) returned `{mfaRequired: true, challengeId, maskedEmail}`
and emailed a 6-digit code. This endpoint accepts the typed code, and
on success returns the same shape as a normal signin response (token +
profile) and sets a long-lived `pria_mfa_trust` cookie that lets the
same browser skip MFA for the next 7 days (or whatever MFA_TRUST_DAYS
sets, bounded to [1, 30]).

**Brute-force protection:** 5 wrong attempts per code; the 6th burns
the challenge (status invalidated) and the user must request a new
code via /mfa-resend. The signin gate further locks the account for
10 minutes after 5 invalidated challenges (with at least one wrong
attempt each) in the previous 1 hour.

**Rate limit:** 100 req/min per IP (authLimiter).




## OpenAPI

````yaml /mdx/api-reference/admin/admin-api.json post /api/auth/mfa-verify
openapi: 3.0.0
info:
  title: Pria Admin API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Admin Memory
    description: Admin inspection and editing of user/instance memory parameters.
  - name: Admin Usage Limits
    description: Per-user usage-vs-cap reporting and account-wide at-limit counts.
paths:
  /api/auth/mfa-verify:
    post:
      tags:
        - Authentication
      summary: Submit a 6-digit MFA code to complete login
      description: |
        Second leg of the MFA login flow. The first leg (POST /api/auth/signin
        or /autosignup) returned `{mfaRequired: true, challengeId, maskedEmail}`
        and emailed a 6-digit code. This endpoint accepts the typed code, and
        on success returns the same shape as a normal signin response (token +
        profile) and sets a long-lived `pria_mfa_trust` cookie that lets the
        same browser skip MFA for the next 7 days (or whatever MFA_TRUST_DAYS
        sets, bounded to [1, 30]).

        **Brute-force protection:** 5 wrong attempts per code; the 6th burns
        the challenge (status invalidated) and the user must request a new
        code via /mfa-resend. The signin gate further locks the account for
        10 minutes after 5 invalidated challenges (with at least one wrong
        attempt each) in the previous 1 hour.

        **Rate limit:** 100 req/min per IP (authLimiter).
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MfaVerifyRequest'
      responses:
        '200':
          description: >-
            Code accepted. Response shape matches POST /api/auth/signin success
            — a JWT token plus the user profile. A Set-Cookie pria_mfa_trust=...
            header is also set.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SignupResponse'
        '400':
          description: Missing challengeId or code.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
        '401':
          description: >-
            Wrong code — `attemptsRemaining` indicates how many tries remain
            before the challenge is invalidated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
        '410':
          description: >-
            Challenge unknown / expired / already verified / cancelled — client
            must restart the signin flow.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
        '423':
          description: >-
            Too many wrong attempts on this code; the challenge is invalidated.
            Request a fresh code via /mfa-resend.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MfaVerifyError'
components:
  schemas:
    MfaVerifyRequest:
      type: object
      required:
        - challengeId
        - code
      properties:
        challengeId:
          type: string
          description: >-
            Opaque server-issued challenge identifier returned by POST
            /api/auth/signin (or /autosignup) when the response carried
            mfaRequired=true.
          example: 65f2c9a1d8e4b3c5a1234567
        code:
          type: string
          pattern: ^[0-9]{6}$
          description: The 6-digit numeric code the user received by email.
          example: '472918'
    SignupResponse:
      type: object
      properties:
        token:
          type: string
          description: JWT authentication token
        profile:
          $ref: '#/components/schemas/UserProfile'
    MfaVerifyError:
      type: object
      properties:
        success:
          type: boolean
          example: false
        code:
          type: string
          enum:
            - BAD_REQUEST
            - WRONG_CODE
            - CHALLENGE_EXPIRED
            - TOO_MANY_ATTEMPTS
            - USER_MISSING
            - RESEND_COOLDOWN
            - MFA_NOT_CONFIGURED
            - MFA_EMAIL_FAILED
        message:
          type: string
        attemptsRemaining:
          type: integer
          description: Only present on WRONG_CODE / TOO_MANY_ATTEMPTS responses.
          example: 4
        retryAfter:
          type: integer
          description: >-
            Seconds the client should wait before retrying. Present on
            RESEND_COOLDOWN.
          example: 24
    UserProfile:
      type: object
      properties:
        _id:
          type: string
        email:
          type: string
          format: email
        fname:
          type: string
        lname:
          type: string
        picture:
          type: string
        accountType:
          type: string
        permissions:
          type: array
          items:
            type: string
        customerId:
          type: string
        lxp_user_id:
          type: string
        lxp_user_type:
          type: integer
        lxp_partner_id:
          type: string
        lxp_partner_name:
          type: string
        lxp_role_id:
          type: integer
        lxp_role_name:
          type: string
        credits:
          type: integer
        creditsUsed:
          type: integer
        plan:
          type: string
        status:
          type: string
        trial_end:
          type: string
          format: date-time
        trial_used:
          type: boolean
        current_period_end:
          type: string
          format: date-time
        cancel_at_period_end:
          type: boolean
        referralId:
          type: string
          format: uuid
        referrerPaid:
          type: boolean
        resetCodeId:
          type: string
          format: uuid
        invoices_urls:
          type: array
          items:
            type: string
        remember_history_count:
          type: integer
        browser_voice:
          type: string
        rt_voice:
          type: string
        use_location:
          type: boolean
        showSideBar:
          type: boolean
        dark_mode:
          type: boolean
        created:
          type: string
          format: date-time
        __v:
          type: integer
        institution:
          $ref: '#/components/schemas/InstitutionProfile'
    InstitutionProfile:
      type: object
      properties:
        _id:
          type: string
        name:
          type: string
        picture:
          type: string
        picture_bg:
          type: string
        picture_dark_bg:
          type: string
        picture_animated:
          type: string
        elevenlabs_agent_id:
          type: string
        credits:
          type: integer
        status:
          type: string
        allowJoining:
          type: string
        joiningAdminOnly:
          type: boolean
        publicId:
          type: string
          format: uuid
        publicAuthorizedUrls:
          type: array
          items:
            type: string
        ainame:
          type: string
        contactEmail:
          type: string
          format: email
        creditAward:
          type: integer
        poolCredits:
          type: boolean
        invoices_urls:
          type: array
          items:
            type: string
        maxCompletionTokens:
          type: integer
        disableFileUploadForUser:
          type: boolean
        disableAudioNotesForUser:
          type: boolean
        toolsDisabled:
          type: array
          items:
            type: string
        ltiContextIds:
          type: array
          items:
            type: string
        personalisationAsked:
          type: boolean
        locationEnabled:
          type: boolean
        rtEnabled:
          type: boolean
        rtAdminOnly:
          type: boolean
        displayAgentDetails:
          type: boolean
        displayThinkingDetails:
          type: boolean
        displayRagSearchDetails:
          type: boolean
        displayThinkingExecution:
          type: boolean
        displayToolExecution:
          type: boolean
        assistantsDisabled:
          type: array
          items:
            type: string
        disableAssistantsForUser:
          type: boolean
        rtVoice:
          type: string
        maxFiles:
          type: integer
        questionType:
          type: string
        creditsTotal:
          type: integer
          nullable: true
        creditsUsagePct:
          type: number
        id:
          type: string

````