---
title: "Validate phone for MFA setup"
method: POST
path: "/v3/mfa/setup/validate"
tags: ["mfa"]
---

# Validate phone for MFA setup

`POST /v3/mfa/setup/validate`

Validate the phone number for setting up MFA in the current organization. This validation requires the `setupId` and `token` from `POST /v3/mfa/setup`.

After the validation is complete, the phone number is registered for the MFA sign in operation.

There are two stages in the BILL MFA process.
1. **MFA setup**: Add a valid phone number for setting up MFA in the organization (with `POST /v3/mfa/setup`), and then complete the setup by validating the entered phone number (with `POST /v3/mfa/validate`). At this point, the phone number is registered for the MFA sign in operation.
2. **MFA sign in**: Generate an MFA challenge (with `POST /v3/mfa/challenge`), and then complete MFA sign in by validating the MFA challenge (with `POST /v3/mfa/challenge/validate`). At this point, your API session is MFA trusted.

**Note**: In the production environment, BILL requires an MFA-trusted API session for a set of API operations.
* Enable vendor `autoPay`
* Enable recurring bill `autoPayment`
* Create a payment or bulk payment
* Create a bank account in a BILL organization
* Reset MFA (Complete MFA setup and MFA sign-in again)

## Headers

- `sessionId` string, nullable — API session ID generated with `/v3/login`
- `devKey` string, nullable — Developer key generated with your BILL developer account

## Request body

- MfaSetupValidateRequestDto — Validate MFA setup
  - `setupId` string, required — MFA `setupId` from the `POST /v3/mfa/setup` response
  - `type` 'VOICE' | 'TEXT', required — Phone type used for MFA setup
  - `token` string, required — Validation `token` sent to the registered phone number

## Response `200`

Validate phone for MFA setup response

- StatusDto — The type Delete response dto.
  - `status` 'SUCCESS' | 'FAILURE' — Request status

## Other responses

- `4XX` — List of errors.
- `5XX` — List of errors.

---

[API](https://skmtc.net/bill/apis/bill-v3-api.md) · [All operations](https://skmtc.net/bill/apis/bill-v3-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/bill/bill-v3-api/revisions/0483350c434e/schema)
