# Organization API: Organizations & Members: Step up

> The 1 Organization API operations for step up.

Source: https://www.coritan.com/docs/api/reference/organizations/organizations-members/step-up/

Part of [Organizations & Members](/docs/api/reference/organizations/organizations-members/).

## Operations

| Method | Path | Summary |
| --- | --- | --- |
| POST | [`/api/v1/orgs/{org_slug}/step-up`](#op-post-api-v1-orgs-org-slug-step-up) | Step up |

### Step up {#op-post-api-v1-orgs-org-slug-step-up}

`POST /api/v1/orgs/{org_slug}/step-up`

Confirm it is you, for the routes that ask first (``reauth_required``):
the ones that move money, end a service or hand the organization over.

Any member, signed in to coritan.com. The body is the account's
``password`` or, while two-factor sign-in is on, a ``code``: the current
one from its authenticator app, or one of its recovery codes, which is
spent. Once two-factor is on the password alone is not enough, as in the
staff console's step-up and for turning two-factor off. The answer's
``token`` goes back as ``X-Org-Step-Up`` on this organization's requests
and counts as a step-up until ``expires_at`` (``max_age_seconds``), for
this account, this organization and this session only.

400 ``code_required`` for a password while two-factor is on; 400
``step_up_failed`` for a wrong password or code, which the audit log
records; 422 without either or with both; 429 past ten tries in five
minutes; 400 ``use_staff_reauth`` for a staff console session, which steps
up with ``POST staff/auth/reauth``.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Request body

`application/json` (required)

| Field | Type | Required |
| --- | --- | --- |
| `password` | string or null | no |
| `code` | string or null | no |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `200` response:

| Field | Type |
| --- | --- |
| `token` | string |
| `expires_at` | string |
| `max_age_seconds` | integer |
