Use this API to register a user's entered time-based one-time password (TOTP) code and mark the user's software token MFA status as "verified" if successful. The request takes an access token or a session string, but not both.
post/#X-Amz-Target=AWSCognitoIdentityProviderService.VerifySoftwareToken
Headers
X-Amz-Target'AWSCognitoIdentityProviderService.VerifySoftwareToken' required
Request body
Response
Success