Skip to content
Coritan Docs

Organization API: Organizations & Members: Step up

The 1 Organization API operations for step up.

View as Markdown

Part of Organizations & Members.

Method Path Summary
POST /api/v1/orgs/{org_slug}/step-up Step up

POST /api/v1/orgs/{org_slug}/step-up

Confirm it is you, for the routes that ask first (reauth_required): the ones that move money, end a service or hand the organization over.

Any member, signed in to coritan.com. The body is the account's password or, while two-factor sign-in is on, a code: the current one from its authenticator app, or one of its recovery codes, which is spent. Once two-factor is on the password alone is not enough, as in the staff console's step-up and for turning two-factor off. The answer's token goes back as X-Org-Step-Up on this organization's requests and counts as a step-up until expires_at (max_age_seconds), for this account, this organization and this session only.

400 code_required for a password while two-factor is on; 400 step_up_failed for a wrong password or code, which the audit log records; 422 without either or with both; 429 past ten tries in five minutes; 400 use_staff_reauth for a staff console session, which steps up with POST staff/auth/reauth.

Name In Type Required
org_slug path string yes

application/json (required)

Field Type Required
password string or null no
code string or null no
Status Meaning
200 Success.
422 The request is not valid. detail lists each problem.

Fields of a 200 response:

Field Type
token string
expires_at string
max_age_seconds integer