Start authenticator app (TOTP) enrolment (session only, step-up).
const url = 'https://api.opdns.io/v1/auth/totp/setup';const options = {method: 'POST', headers: {cookie: 'opdns_session=<opdns_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.opdns.io/v1/auth/totp/setup \ --cookie opdns_session=<opdns_session>Returns a new RFC 6238 secret (SHA-1, 6 digits, 30 s) and its otpauth:// URI
for a QR code. The secret is stored encrypted and stays inactive until
POST /v1/auth/totp/confirm receives a valid code; calling setup again
replaces an unconfirmed secret. 409 totp_already_enabled when TOTP is on.
Needs a sign-in within the last five minutes (reauth_required). Allowed for
a restricted session.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”Secret to enrol.
object
Base32 secret for manual entry.
otpauth://totp/... URI to render as a QR code.
Example
{ "digits": 6, "period": 30}Not authenticated.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/unauthenticated", "title": "Unauthorized", "status": 401, "code": "unauthenticated", "detail": "authentication required", "request_id": "5f2c9a0e7b1d4c38"}Authenticated but not allowed: insufficient_scope, session_required, csrf_rejected, mfa_enrolment_required (restricted session), mfa_required (an operator action, or an admin-scoped token, from a session signed in with the password alone; not in dev), reauth_required (sign in again within five minutes), account_pending_deletion (the account is in its deletion cooling-off).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/insufficient_scope", "title": "Forbidden", "status": 403, "code": "insufficient_scope", "detail": "the token lacks the profiles:write scope", "request_id": "5f2c9a0e7b1d4c38"}Conflict. On POSTs with an Idempotency-Key: idempotency_key_reused (the key was used with a different request) or idempotency_in_progress (the first request with it is still running; retry after Retry-After).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/idempotency_key_reused", "title": "Conflict", "status": 409, "code": "idempotency_key_reused", "detail": "the Idempotency-Key was used with a different request", "request_id": "5f2c9a0e7b1d4c38"}