[{"data":1,"prerenderedAt":413},["ShallowReactive",2],{"navigation":3,"\u002Fexamples\u002Ftwo-factor":139,"\u002Fexamples\u002Ftwo-factor-surround":408},[4,48,79,98],{"title":5,"path":6,"stem":7,"children":8,"icon":47},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27,32,37,42],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"AI agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F3.ai-agents","i-lucide-bot",{"title":23,"path":24,"stem":25,"icon":26},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F4.quick-start","i-lucide-play",{"title":28,"path":29,"stem":30,"icon":31},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F5.configuration","i-lucide-settings",{"title":33,"path":34,"stem":35,"icon":36},"Production","\u002Fgetting-started\u002Fproduction","1.getting-started\u002F6.production","i-lucide-shield-check",{"title":38,"path":39,"stem":40,"icon":41},"Compare","\u002Fgetting-started\u002Fcompare","1.getting-started\u002F7.compare","i-lucide-git-compare",{"title":43,"path":44,"stem":45,"icon":46},"FAQ","\u002Fgetting-started\u002Ffaq","1.getting-started\u002F8.faq","i-lucide-circle-help","i-lucide-rocket",{"title":49,"path":50,"stem":51,"children":52,"icon":54},"Examples","\u002Fexamples","2.examples\u002F1.index",[53,55,60,65,70,74],{"title":49,"path":50,"stem":51,"icon":54},"i-lucide-waypoints",{"title":56,"path":57,"stem":58,"icon":59},"Register a confirmed account","\u002Fexamples\u002Fregister-confirmed-account","2.examples\u002F2.register-confirmed-account","i-lucide-mail-check",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fexamples\u002Freset-forgotten-password","2.examples\u002F3.reset-forgotten-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Enable and disable two-factor authentication","\u002Fexamples\u002Ftwo-factor","2.examples\u002F4.two-factor","i-lucide-smartphone",{"title":71,"path":72,"stem":73,"icon":36},"Complete step-up (ReAuth)","\u002Fexamples\u002Freauth","2.examples\u002F5.reauth",{"title":75,"path":76,"stem":77,"icon":78},"Sign in with a passkey","\u002Fexamples\u002Fpasskey-sign-in","2.examples\u002F6.passkey-sign-in","i-lucide-fingerprint",{"title":80,"path":81,"stem":82,"children":83,"icon":97},"Composable Endpoints","\u002Fcomposables","3.composables\u002F1.index",[84,87,92],{"title":85,"path":81,"stem":82,"icon":86},"Overview","i-lucide-layout-grid",{"title":88,"path":89,"stem":90,"icon":91},"Requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements","i-lucide-list-checks",{"title":93,"path":94,"stem":95,"icon":96},"Recipes","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":99,"icon":100,"path":101,"stem":102,"children":103,"page":138},"Modules","i-lucide-package","\u002Fmodules","4.modules",[104,109,114,119,123,128,133],{"title":105,"path":106,"stem":107,"icon":108},"Identity management","\u002Fmodules\u002Fidentity-management","4.modules\u002F1.identity-management","i-lucide-user-cog",{"title":110,"path":111,"stem":112,"icon":113},"Cookie auth","\u002Fmodules\u002Fcookie-auth","4.modules\u002F2.cookie-auth","i-lucide-cookie",{"title":115,"path":116,"stem":117,"icon":118},"Bearer auth","\u002Fmodules\u002Fbearer-auth","4.modules\u002F3.bearer-auth","i-lucide-key",{"title":120,"path":121,"stem":122,"icon":78},"JWT","\u002Fmodules\u002Fjwt","4.modules\u002F4.jwt",{"title":124,"path":125,"stem":126,"icon":127},"Passkeys","\u002Fmodules\u002Fpasskeys","4.modules\u002F5.passkeys","i-lucide-scan-face",{"title":129,"path":130,"stem":131,"icon":132},"ReAuth","\u002Fmodules\u002Freauth","4.modules\u002F6.reauth","i-lucide-shield-alert",{"title":134,"path":135,"stem":136,"icon":137},"External OAuth","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F7.external-oauth","i-lucide-log-in",false,{"id":140,"title":66,"body":141,"description":401,"extension":402,"links":403,"meta":404,"navigation":405,"path":67,"seo":406,"stem":68,"__hash__":407},"docs\u002F2.examples\u002F4.two-factor.md",{"type":142,"value":143,"toc":390},"minimark",[144,165,175,180,198,202,257,268,272,294,300,304,344,348,371,375],[145,146,147,148,152,153,156,157,160,161,164],"p",{},"Manage authenticator 2FA for a signed-in user. Paths are under ",[149,150,151],"code",{},"\u002Fidentity\u002Fmanage\u002F2fa",". ",[149,154,155],{},"POST"," requires authorization, CSRF (",[149,158,159],{},"RequestVerificationToken","), and ReAuth. Body shape is Identity ",[149,162,163],{},"TwoFactorRequest",".",[145,166,167,168,171,172,164],{},"Assume cookie session (",[149,169,170],{},"credentials: \"include\"",") and a fresh CSRF token from ",[149,173,174],{},"GET \u002Fidentity\u002FcsrfToken",[176,177,179],"h2",{"id":178},"read-status","Read status",[181,182,183,187,192],"ol",{},[184,185,186],"li",{},"Sign in.",[184,188,189,164],{},[149,190,191],{},"GET \u002Fidentity\u002Fmanage\u002F2fa",[184,193,194,195,164],{},"Response includes ",[149,196,197],{},"isTwoFactorEnabled",[176,199,201],{"id":200},"enable","Enable",[181,203,204,211,225,228,231,240],{},[184,205,206,207,210],{},"Complete step-up: ",[208,209,71],"a",{"href":72}," (password, 2FA, or passkey proof).",[184,212,213,214,217,218,221,222,164],{},"Mint or refresh the authenticator shared key with ",[149,215,216],{},"POST \u002Fidentity\u002Fmanage\u002F2fa"," and body ",[149,219,220],{},"{}"," (plus CSRF). When no key exists, the response includes ",[149,223,224],{},"sharedKey",[184,226,227],{},"Show the shared key (or QR) in the authenticator app.",[184,229,230],{},"Complete ReAuth again if the ReAuth cookie expired (5 minutes).",[184,232,233,235,236,239],{},[149,234,216],{}," with ",[149,237,238],{},"{ \"enable\": true, \"twoFactorCode\": \"\u003C6-digit TOTP>\" }"," and CSRF.",[184,241,242,243,246,247,250,251,253,254,164],{},"On ",[149,244,245],{},"200",", store ",[149,248,249],{},"recoveryCodes"," from the response when present. ",[149,252,197],{}," is ",[149,255,256],{},"true",[145,258,259,260,263,264,267],{},"Do not send ",[149,261,262],{},"enable: true"," together with ",[149,265,266],{},"resetSharedKey: true",". That combination returns a validation problem.",[176,269,271],{"id":270},"disable","Disable",[181,273,274,277,284],{},[184,275,276],{},"Complete ReAuth.",[184,278,279,235,281,239],{},[149,280,216],{},[149,282,283],{},"{ \"enable\": false }",[184,285,242,286,288,289,253,291,164],{},[149,287,245],{},", ",[149,290,197],{},[149,292,293],{},"false",[145,295,296,297,299],{},"To rotate the authenticator key, set ",[149,298,266],{}," (this also disables 2FA until you enable again with a code from the new key).",[176,301,303],{"id":302},"optional-flags-on-post","Optional flags on POST",[305,306,307,320],"table",{},[308,309,310],"thead",{},[311,312,313,317],"tr",{},[314,315,316],"th",{},"Field",[314,318,319],{},"Effect",[321,322,323,334],"tbody",{},[311,324,325,331],{},[326,327,328],"td",{},[149,329,330],{},"resetRecoveryCodes",[326,332,333],{},"Issues a new set of recovery codes",[311,335,336,341],{},[326,337,338],{},[149,339,340],{},"forgetMachine",[326,342,343],{},"Clears the two-factor remember-client cookie",[176,345,347],{"id":346},"sign-in-after-2fa-is-enabled","Sign in after 2FA is enabled",[145,349,350,351,235,354,288,357,360,361,364,365,368,369,164],{},"Password cookie login: ",[149,352,353],{},"POST \u002Fidentity\u002Flogin",[149,355,356],{},"email",[149,358,359],{},"password",", and either ",[149,362,363],{},"twoFactorCode"," or ",[149,366,367],{},"twoFactorRecoveryCode"," when Identity requires 2FA. Login does not require CSRF. See ",[208,370,110],{"href":111},[176,372,374],{"id":373},"related","Related",[376,377,378,382,386],"ul",{},[184,379,380],{},[208,381,71],{"href":72},[184,383,384],{},[208,385,105],{"href":106},[184,387,388],{},[208,389,129],{"href":130},{"title":391,"searchDepth":392,"depth":393,"links":394},"",1,2,[395,396,397,398,399,400],{"id":178,"depth":393,"text":179},{"id":200,"depth":393,"text":201},{"id":270,"depth":393,"text":271},{"id":302,"depth":393,"text":303},{"id":346,"depth":393,"text":347},{"id":373,"depth":393,"text":374},"Turn authenticator 2FA on or off with CSRF and ReAuth.","md",null,{},{"icon":69},{"title":66,"description":401},"PRwyCf7sVBxruXscX998EROw6p2Ltqy1BaRzbM3anZ0",[409,411],{"title":61,"path":62,"stem":63,"description":410,"icon":64,"children":-1},"Request a reset mail, set a new password, then sign in.",{"title":71,"path":72,"stem":73,"description":412,"icon":36,"children":-1},"Prove identity before a CSRF-protected manage or host action.",1789052353188]