Skip to content

Security and sign-in

Start two-factor enrolment

POST/api/me/mfa/enrol

Needs the current password. Answers with the TOTP secret and an otpauth:// URL for the authenticator app.

#Authentication

Session cookie

A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.