---
title: "Use a one-time recovery code to satisfy a two-factor authentication requirement."
method: POST
path: "/mf-recovery"
---

# Use a one-time recovery code to satisfy a two-factor authentication requirement.

`POST /mf-recovery`

## Request body

- object
  - `code` string — One-time recovery code

## Response `200`

Successful authentication.

- DefaultJsonResponse
  - `meta` object, required
    - `code` integer, required — Http status code
  - `response` object, required
    - `user` object — By default an empty dictionary is returned. However by overriding _User::get_security_payload()_ any attributes of the User model can be returned.
    - `csrf_token` string — Session CSRF token

## Other responses

- `302` — Successful login
- `400` — Error when validating code.

---

[API](https://skmtc.net/pallets-eco/apis/flask-security-external-api.md) · [All operations](https://skmtc.net/pallets-eco/apis/flask-security-external-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/pallets-eco/flask-security-external-api/versions/5ee7c28d6e1e/schema)
