Security and sign-in
Confirm two-factor enrolment
POST
/api/me/mfa/confirmA first code from the app turns it on and returns recovery codes, once.
#Authentication
Session cookie
A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.