---
title: "Unregister MFA for the user"
method: POST
path: "/v2/users/{userId}/mfa/unregister"
tags: ["Users"]
---

# Unregister MFA for the user

`POST /v2/users/{userId}/mfa/unregister`

Unregister the MFA device for the user

If the user does not require further verification then a register new MFA device token will be sent to them via their email address

## Path parameters

- `userId` string, uuid, required

## Request body

- UnregisterMFARequest
  - `mfaType` 'YUBIKEY' | 'TOTP', required — The type of the MFA device
  - `verificationCode` string, nullable — <p>Optional property that MUST be suppied when manually verifying a user</p> <p>The user's smsNumber is registered via a separate endpoint and an OTP sent to them</p>

## Response `204`

the MFA Type to unregister

## Other responses

- `400` — Invalid request. See Error message payload for details of failure
- `401` — Invalid access token. May be expired or invalid
- `403` — The authentication does not have permissions to access the resource This usually occurs when there is a valid authentication instance (client or user) but they do not have the required permissions
- `404` — The resource was not found or is no longer available

---

[API](https://skmtc.net/velopaymentsapi/apis/velo-payments-apis.md) · [All operations](https://skmtc.net/velopaymentsapi/apis/velo-payments-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/velopaymentsapi/velo-payments-apis/versions/05c3f09fc50a/schema)
