Upsun MFA API

Multi-factor authentication (MFA) requires the user to present two (or more) types of evidence (or factors) to prove their identity. For example, the evidence might be a password and a device-generated code, which show the user has the knowledge factor ("something you know") as well as the possession factor ("something you have"). In this way MFA offers good protection against the compromise of any single factor, such as a stolen password. Using the MFA API you can set up time-based one-time passcodes (TOTP), which can be generated on a single registered device ("something you have") such as a mobile phone.

Business capability
Identity & Access Management BC-620.20

Operations 8

GET /users/{user_id}/totp Get information about TOTP enrollment #
POST /users/{user_id}/totp Confirm TOTP enrollment #
DELETE /users/{user_id}/totp Withdraw TOTP enrollment #
POST /users/{user_id}/codes Re-create recovery codes #
GET /organizations/{organization_id}/mfa-enforcement Get organization MFA settings #
POST /organizations/{organization_id}/mfa-enforcement/enable Enable organization MFA enforcement #
POST /organizations/{organization_id}/mfa-enforcement/disable Disable organization MFA enforcement #
POST /organizations/{organization_id}/mfa/remind Send MFA reminders to organization members #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/upsun-mfa-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

upsun-mfa-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Upsun.com Rest MFA API
  version: '1.0'
  contact:
    name: Support
    url: https://upsun.com/contact-us/
  termsOfService: https://upsun.com/trust-center/legal/tos/
  description: '# Introduction


    Upsun, formerly Platform.sh, is a container-based Platform-as-a-Service.'
  x-logo:
    url: https://docs.upsun.com/images/upsun-api.svg
    href: https://upsun.com/#section/Introduction
    altText: Upsun logo
servers:
- url: '{schemes}://api.upsun.com'
  description: The Upsun.com API gateway
  variables:
    schemes:
      default: https
security:
- OAuth2: []
tags:
- name: MFA
  description: Multi-factor authentication (MFA) requires the user to present two (or more) types of evidence (or factors) to prove their identity.
paths:
  /users/{user_id}/totp:
    parameters:
    - $ref: '#/components/parameters/UserID'
    get:
      summary: Get information about TOTP enrollment
      description: Retrieves TOTP enrollment information.
      operationId: get-totp-enrollment
      tags:
      - MFA
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  issuer:
                    type: string
                    format: uri
                    description: ''
                  account_name:
                    type: string
                    description: Account name for the enrollment.
                  secret:
                    type: string
                    description: The secret seed for the enrollment
                  qr_code:
                    type: string
                    format: byte
                    description: Data URI of a PNG QR code image for the enrollment.
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: Conflict
    post:
      summary: Confirm TOTP enrollment
      description: Confirms the given TOTP enrollment.
      operationId: confirm-totp-enrollment
      tags:
      - MFA
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  recovery_codes:
                    type: array
                    description: A list of recovery codes for the MFA enrollment.
                    items:
                      type: string
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                secret:
                  type: string
                  description: The secret seed for the enrollment
                passcode:
                  type: string
                  description: TOTP passcode for the enrollment
              required:
              - secret
              - passcode
        description: ''
    delete:
      summary: Withdraw TOTP enrollment
      description: Withdraws from the TOTP enrollment.
      operationId: withdraw-totp-enrollment
      tags:
      - MFA
      responses:
        '204':
          description: No Content
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not Found
  /users/{user_id}/codes:
    parameters:
    - $ref: '#/components/parameters/UserID'
    post:
      summary: Re-create recovery codes
      description: Re-creates recovery codes for the MFA enrollment.
      operationId: recreate-recovery-codes
      tags:
      - MFA
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                type: object
                properties:
                  recovery_codes:
                    type: array
                    description: A list of recovery codes for the MFA enrollment.
                    items:
                      type: string
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not Found
  /organizations/{organization_id}/mfa-enforcement:
    get:
      summary: Get organization MFA settings
      description: Retrieves MFA settings for the specified organization.
      operationId: get-org-mfa-enforcement
      tags:
      - MFA
      parameters:
      - $ref: '#/components/parameters/OrganizationIDName'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationMFAEnforcement'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /organizations/{organization_id}/mfa-enforcement/enable:
    post:
      summary: Enable organization MFA enforcement
      description: Enables MFA enforcement for the specified organization.
      operationId: enable-org-mfa-enforcement
      tags:
      - MFA
      parameters:
      - $ref: '#/components/parameters/OrganizationID'
      responses:
        '204':
          description: No Content
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /organizations/{organization_id}/mfa-enforcement/disable:
    post:
      summary: Disable organization MFA enforcement
      description: Disables MFA enforcement for the specified organization.
      operationId: disable-org-mfa-enforcement
      tags:
      - MFA
      parameters:
      - $ref: '#/components/parameters/OrganizationID'
      responses:
        '204':
          description: No Content
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /organizations/{organization_id}/mfa/remind:
    post:
      summary: Send MFA reminders to organization members
      description: Sends a reminder about setting up MFA to the specified organization members.
      operationId: send-org-mfa-reminders
      tags:
      - MFA
      parameters:
      - $ref: '#/components/parameters/OrganizationID'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                user_ids:
                  type: array
                  description: The organization members.
                  items:
                    type: string
                    format: uuid
                    description: The ID of the user.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                additionalProperties:
                  type: object
                  properties:
                    code:
                      type: integer
                      description: An HTTP-like status code referring to the result of the operation for the specific user.
                    message:
                      type: string
                      description: A human-readable message describing the result of the operation for the specific user
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  parameters:
    OrganizationIDName:
      in: path
      name: organization_id
      description: 'The ID of the organization.<br>

        Prefix with name= to retrieve the organization by name instead.

        '
      required: true
      schema:
        type: string
    UserID:
      name: user_id
      in: path
      required: true
      description: The ID of the user.
      schema:
        type: string
        example: d81c8ee2-44b3-429f-b944-a33ad7437690
        format: uuid
    OrganizationID:
      name: organization_id
      in: path
      required: true
      description: The ID of the organization.
      schema:
        type: string
        format: ulid
  schemas:
    Error:
      description: ''
      type: object
      properties:
        status:
          type: string
        message:
          type: string
        code:
          type: number
        detail:
          type: object
        title:
          type: string
      title: ''
      x-examples:
        example-1:
          status: Invalid input
          message: This field is required.
          code: 400
          detail:
            field:
            - This field is required.
          title: Bad Request
    OrganizationMFAEnforcement:
      description: The MFA enforcement for the organization.
      type: object
      properties:
        enforce_mfa:
          type: boolean
          description: Whether the MFA enforcement is enabled.
      x-examples:
        example-1:
          enforce_mfa: true
  securitySchemes:
    OAuth2:
      type: oauth2
      flows:
        authorizationCode:
          tokenUrl: https://auth.api.platform.sh/oauth2/token
          refreshUrl: https://auth.api.platform.sh/oauth2/token
          scopes: {}
          authorizationUrl: https://auth.api.platform.sh/oauth2/authorize
      description: ''
    OAuth2Admin:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://auth.api.platform.sh/oauth2/token
          refreshUrl: ''
          scopes:
            admin: administrative operations
      description: ''
x-tagGroups:
- name: Organization Administration
  tags:
  - Organizations
  - Organization Members
  - Organization Invitations
  - Organization Projects
  - Add-ons
- name: Project Administration
  tags:
  - Project
  - Domain Management
  - Cert Management
  - Certificate Provisioner
  - Project Variables
  - Repository
  - Third-Party Integrations
  - Support
- name: Environments
  tags:
  - Environment
  - Environment Backups
  - Environment Type
  - Environment Variables
  - Routing
  - Source Operations
  - Runtime Operations
  - Deployment
  - Autoscaling
- name: User Activity
  tags:
  - Project Activity
  - Environment Activity
- name: Project Access
  tags:
  - Project Invitations
  - Teams
  - Team Access
  - User Access
- name: Account Management
  tags:
  - API Tokens
  - Connections
  - MFA
  - Users
  - User Profiles
  - SSH Keys
  - Plans
- name: Billing
  tags:
  - Organization Management
  - Subscriptions
  - Orders
  - Invoices
  - Discounts
  - Vouchers
  - Records
  - Profiles
- name: Global Info
  tags:
  - Project Discovery
  - References
  - Regions
- name: Internal APIs
  tags:
  - Project Settings
  - Environment Settings
  - Deployment Target
  - System Information
  - Container Profile