---
title: "Generate MFA challenge"
method: POST
path: "/v3/mfa/challenge"
tags: ["mfa"]
---

# Generate MFA challenge

`POST /v3/mfa/challenge`

Generate an MFA challenge ID for creating an MFA-trusted API sign in session.

In the response, a `challengeId` is generated and a six-digit `token` is sent to the phone number that was registered with MFA setup.

After you generate a challenge ID (with `POST /v3/mfa/challenge`), complete your MFA sign in by validating the MFA challenge (with `POST /v3/mfa/challenge/validate`). At this point, your API session is MFA trusted.

There are two stages in the BILL MFA process.
1. **MFA setup**: Add a valid phone number for setting up MFA in the organization (with `POST /v3/mfa/setup`), and then complete the setup by validating the entered phone number (with `POST /v3/mfa/validate`). At this point, the phone number is registered for the MFA sign in operation.
2. **MFA sign in**: Generate an MFA challenge (with `POST /v3/mfa/challenge`), and then complete MFA sign in by validating the MFA challenge (with `POST /v3/mfa/challenge/validate`). At this point, your API session is MFA trusted.

**Note**: In the production environment, BILL requires an MFA-trusted API session for a set of API operations.
* Enable vendor `autoPay`
* Enable recurring bill `autoPayment`
* Create a payment or bulk payment
* Create a bank account in a BILL organization
* Reset MFA (Complete MFA setup and MFA sign-in again)

## Headers

- `sessionId` string, nullable — API session ID generated with `/v3/login`
- `devKey` string, nullable — Developer key generated with your BILL developer account

## Request body

- MfaChallengeRequestDto — Generate MFA challenge
  - `useBackup` boolean — Set as `false` to generate the token with the primary device. The default value is `false`.

## Response `200`

Generate MFA challenge response

- MfaChallengeResponseDto — Response for MFA challenge.
  - `challengeId` string — MFA challenge ID. This value is required for validating the MFA challenge with `POST /v3/mfa/challenge/validate`.

## Other responses

- `4XX` — List of errors.
- `5XX` — List of errors.

---

[API](https://skmtc.net/bill/apis/bill-v3-api.md) · [All operations](https://skmtc.net/bill/apis/bill-v3-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/bill/bill-v3-api/revisions/0483350c434e/schema)
