KIO Link
KIO Link XC APIKIO Link API
KIO BMSHuawei BMSHuawei Alert
KIO Link XC APIKIO Link API
KIO BMSHuawei BMSHuawei Alert
  1. Auth
  • Auth
    • Overview
    • Log in
      POST
    • Send a one-time sign-in token
      POST
    • Log in with Apple
      POST
    • Validate a session token
      GET
    • Sign in with a one-time sign-in token
      POST
    • Request a password reset
      POST
    • Get the user of a password reset token
      GET
    • Reset a password
      POST
    • Submit a business registration request
      POST
    • Enable two-factor authentication
      POST
    • Confirm a two-factor login
      POST
  • Application Content
    • List application content
    • Create application content
    • Get application content by slug
    • Get application content by public id
    • Partially update application content
    • Delete application content
  • Businesses
    • Overview
    • Business Users
      • Overview
      • List business users by business
      • List a business's users
      • Create a business user
      • Get a business user
      • Update a business user
      • Upload a business user's avatar
      • Delete a business user's avatar
      • Deactivate business users
      • Search business users
      • Search a business's users
      • Send a password reset email to a business user
      • Reset a business user's daily sign-in code limits
      • Toggle a business user's two-factor authentication
      • Import business users from CSV
      • Export all business users
      • Set whether I receive releases
      • Set whether I receive alerts
      • Request the deletion of my account
    • Business Roles
      • Overview
      • List business user roles
      • Create a business user role
      • Get a business user role
      • Update a business user role
      • Delete a business user role
    • Business Permissions
      • Overview
      • List business user permissions
      • Create a business user permission
      • Delete a business user permission
    • Business Consoles
      • Overview
      • List a business's consoles
      • Create a business console
      • Delete a business console
    • Business Devices
      • Overview
      • List a business's devices
      • Search a business's devices
      • Export all business devices
      • Export my business's devices
      • Import business devices from CSV
      • Start device transfers from CSV
      • Import device statuses from CSV
      • Delete business devices
      • Change a device's owner
      • Get a business's device transfer log
    • Business Racks
      • Overview
      • Export all business racks
      • Assign a rack to a business
      • List a business's racks
      • List all business racks
      • Change a business rack's status
      • Delete business racks
      • Restore a deleted business rack
      • Import business racks from CSV
    • Business Locations
      • Overview
      • Update a business's status and datacenters
      • Migrate business locations to datacenters
      • Remove the old locations field from businesses
      • Migrate business user locations to datacenters
      • Migrate business device locations to datacenter names
    • Business Reports
      • Overview
      • Send the visits reports
      • Download a visits report
      • Set a business's report recipients
    • List businesses
    • Search businesses
    • Search businesses by name or extra data
    • Export businesses
    • Get a business
    • Create a business
    • Import businesses from CSV
    • Update a business
    • Delete a business
  • Banned Devices
    • List banned devices
    • Check if a device is risky or banned
    • Get a banned device
    • Create a banned device
    • Update a banned device
    • Delete a banned device
  • Data Centers
    • Listar data centers
    • Crear un data center
    • Actualizar un data center
    • Eliminar un data center
  • Intake Forms
    • List intake form reponses
    • Get an intake form's response
    • Get an intake form's response license file
    • Get an intake form's response identification file
    • Download intake form responses report
    • Create an intake form's response
    • Upload a license file to an intake form's response
    • Upload an identification file to an intake form's response
    • Update an intake form's response
    • Delete an intake form's response
  • Users
    • Overview
    • Permissions
      • Overview
      • Generate KIO user permissions
      • Generate business user permissions
      • List KIO user permissions
      • Create a KIO user permission
      • Delete a KIO user permission
    • Roles
      • Overview
      • List KIO user roles
      • Create a KIO user role
      • Get a KIO user role
      • Update a KIO user role
      • Delete a KIO user role
    • User Groups
      • Overview
      • List user groups
      • Create a user group
      • Update a user group
      • Delete a user group
    • List KIO users
    • Create a KIO user
    • Get a KIO user
    • Update a KIO user
    • Activate or deactivate a KIO user
    • Delete a KIO user
    • Generate a session token for a user
    • Export KIO users
    • Search active KIO users by name
    • Search KIO users
    • Look up an employee in SuccessFactors
    • Import KIO user updates from CSV
  • External Users
    • Overview
    • List external users
    • Find external users to invite
    • Search external users
    • Export external users
    • Create an external user
    • Edit an external user
    • Update an external user
    • Upload an external user's avatar
    • Delete an external user's avatar
    • Delete an external user
  • Send App Notification
    POST
  • Events Locations
    GET
  • Fetch Wires
    GET
  • Create Business Temporary Secret
    POST
  • Schemas
    • Auth
      • Auth Session
      • Two-Factor Status
      • Two-Factor Challenge
      • KIO User Session
    • Businesses
      • Business Users
        • Business User Role
        • Datacenter Access
        • Business User
        • Business User With Relations
        • Business User Permission
      • Business Devices
        • Business Device
        • Business Device Log Entry
      • Business Racks
        • Business Rack
        • Datacenter Rack
      • Business
      • Datacenter Assignment
      • Business List Item
      • Business Console
    • Users
      • User Role
      • User
      • User Permission
      • User Group
      • Permission Catalog
      • SuccessFactors Employee
    • External Users
      • External User
    • ApplicationContentCreate
    • ApplicationContentUpdate
    • ApplicationContent
    • ApplicationContentListResponse
    • Banned Device
    • Error
    • LanguageEntry
    • Pagination
    • Intake Form
    • DataCenter
    • LocalizedContent
    • Delete Result
    • Import Row Error
    • Bulk Write Result
    • Message
    • Personal Device
  1. Auth

Confirm a two-factor login

QA Environment
https://qa-api.kiolinkapp.com
QA Environment
https://qa-api.kiolinkapp.com
POST
https://qa-api.kiolinkapp.com
/v1/auth/confirm-login-2fa
Auth
Last modified:2026-10-05 20:03:21
Maintainer:Not configured
Finishes a password sign-in that returned HTTP 202 from Log in, using the code emailed to the user.
two_fa_otp must match two_fa_session_id (case-insensitive, surrounding spaces ignored).
The code expires 5 minutes after it is sent and can only be used once.
On success, 2FA stays active, a new grace period starts (two_fa.refreshed_limit_date) and the sign-in counts toward the daily limit.
This endpoint is public.

Request

Body Params application/jsonRequired

Example
{
  "two_fa_session_id": "3F9A1C",
  "two_fa_otp": "3F9A1C"
}

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location 'https://qa-api.kiolinkapp.com/v1/auth/confirm-login-2fa' \
--header 'authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '{
  "two_fa_session_id": "3F9A1C",
  "two_fa_otp": "3F9A1C"
}'

Responses

🟢200Signed in
application/json
Signed in.
Bodyapplication/json

Example
{
    "user": {
        "_id": "65f1c2a9e4b0a1b2c3d4e5f6",
        "firstname": "Ana",
        "lastname": "López",
        "email": "ana.lopez@example.com",
        "password": "$2b$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy",
        "devices": [],
        "dc_access": {
            "_id": "65f1c2a9e4b0a1b2c3d4e5c3",
            "days": [
                1,
                2,
                3,
                4,
                5
            ],
            "from": "08:00",
            "to": "20:00",
            "locations": [
                {
                    "_id": "65f1c2a9e4b0a1b2c3d4e602",
                    "datacenter": "MEX1",
                    "status": true,
                    "fases": [
                        "F1"
                    ]
                }
            ],
            "datacenters": [
                "65f1c2a9e4b0a1b2c3d4e5d4"
            ],
            "_business": "65f1c2a9e4b0a1b2c3d4e5a1",
            "_business_user": "65f1c2a9e4b0a1b2c3d4e5f6",
            "_authorized_business_user": "65f1c2a9e4b0a1b2c3d4e5f6",
            "request_date": "2025-01-10T16:00:00.000Z",
            "authorized_date": "2025-01-11T09:30:00.000Z",
            "status": "Autorizada",
            "authorizer_name": "Ana López",
            "authorizer_email": "ana.lopez@example.com",
            "__v": 0
        },
        "device_tokens": [],
        "consoles": [],
        "active": true,
        "role": {
            "_id": "65f1c2a9e4b0a1b2c3d4e5b2",
            "name": "Administrador",
            "slug": "admin",
            "show_in_releases": true,
            "__v": 0
        },
        "business": {
            "_id": "65f1c2a9e4b0a1b2c3d4e5a1",
            "name": "Digital Ignition",
            "normalized_name": "digital ignition",
            "calle": "Av. Prolongación Paseo de la Reforma 5287",
            "colonia": "Cuajimalpa",
            "municipio": "Cuajimalpa de Morelos",
            "estado": "Ciudad de México",
            "pais": "México",
            "cp": "05000",
            "tel": "5550000000",
            "id_salesforce": "0015e00000AbCdEAAV",
            "admin": "65f1c2a9e4b0a1b2c3d4e5f6",
            "active": 1,
            "traffic_light": false,
            "extradata": [],
            "datacenters": [
                {
                    "_id": "65f1c2a9e4b0a1b2c3d4e601",
                    "datacenter": "MEX1",
                    "status": true,
                    "fases": [
                        "F1",
                        "F2"
                    ]
                }
            ],
            "created_at": "2024-03-13T18:22:01.000Z",
            "ejecutivo_finanzas": "finanzas@kio.tech",
            "ejecutivo_finanzas_backup": "",
            "preauthorization": false,
            "_report_business_user": [
                "65f1c2a9e4b0a1b2c3d4e5f6"
            ],
            "_report_kio_user": [],
            "language_report": "es",
            "business_channel": false,
            "business_main": null,
            "qrform": false,
            "has_drwp": false,
            "is_kio_business": false,
            "is_xc_active": true,
            "is_ic_active": false,
            "__v": 0
        },
        "created_at": "2024-03-13T18:22:01.000Z",
        "level": "Administrador",
        "show_in_releases": true,
        "show_in_alerts": true,
        "time_zone": "America/Mexico_City",
        "verify_email": "deliverable",
        "delete_request": false,
        "id_service_desk_plus": "0",
        "two_factor_auth_activated": true,
        "two_factor_auth_limit_date": "04-11-2026",
        "two_factor_auth_unavailable": false,
        "password_limit_date": "2027-01-03T19:00:00.000Z",
        "sent_feedback": false,
        "__v": 0
    },
    "token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJfaWQiOiI2NWYxYzJhOWU0YjBhMWIyYzNkNGU1ZjYifQ.c2lnbmF0dXJl",
    "permissions": [
        "xc-requests",
        "kiolink-events"
    ],
    "two_fa": {
        "required": false,
        "verified": true,
        "refreshed_limit_date": "04-11-2026",
        "grace_days_config": 30
    }
}
🟠400A field is missing, or the code does not match the session
🟠404The 2FA session does not exist, was already used or expired,
🟠405The user's business is inactive
🔴500Unexpected error
Modified at 2026-10-05 20:03:21
Previous
Enable two-factor authentication
Next
List application content
Built with