Console · Published 2026-09-28 · Updated 2026-09-28 · AgentiSend
Security
Turn on a second factor, copy the recovery codes once, and sign out other sessions. These calls are not in the published API reference.
Security is at /settings/security. It enrols a second factor for the signed-in person, lists other signed-in sessions, and (for an owner) requires a second factor of everyone on the account.
What the screen calls
These routes are not in the published API reference, so this page has no sample built from that reference. The screen calls them on the signed-in session:
GET /api/auth/mfareads whether a second factor is on, and how many recovery codes are unused.POST /api/auth/mfa/enrollstarts enrolment.POST /api/auth/mfa/verifyfinishes it and returns the recovery codes.POST /api/auth/mfa/disableturns it off.GET /api/auth/sessionslists sessions.POST /api/auth/sessions/revoke-otherssigns the others out.GET /account/securityreads whether the account requires a second factor, and the caller's role.PATCH /account/securitysets that requirement. Only an owner can change it.
Enrolment returns 10 recovery codes, once. They are not shown again. There is no call that mints a new set. Turning the second factor off deletes the codes that are left.
A sign-in that has not finished the second factor is refused with:
{
"error": {
"code": "mfa_required",
"message": "This session has not completed two-factor authentication.",
"fix": "Finish signing in at https://console.agentisend.com/verify with a code from your authenticator app, or one of your recovery codes. Manage the second factor in the console under Settings, Security.",
"docs_url": "https://agentisend.com/docs/errors#mfa_required",
"retryable": false
}
}Limits of this screen
The control that requires a second factor of everyone is shown when the role is owner, and also when the role comes back empty. An empty role is then refused. That refusal uses the code forbidden, which is not in the error catalogue.
The second-factor and session routes also answer with codes that are not in the catalogue: unauthenticated, mfa_reauth_required, mfa_already_enabled, mfa_code_invalid, mfa_not_enabled, mfa_required_by_account, validation_failed and rate_limited. The catalogue code for a half-finished sign-in is mfa_required, above.