POST /v1/auth/login (HTTP 202) when the user's 2FA grace period has ended. A code was emailed to the user; finish signing in with POST /v1/auth/confirm-login-2fa.{
"two_fa_required": true,
"two_fa_session_id": "3F9A1C",
"message": "A two-factor authentication code has been sent to your email. Use it with POST /v1/auth/confirm-login-2fa",
"email": "ana.lopez@example.com",
"grace_days_config": 30
}