> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Initiate MFA Setup

> Initiates MFA setup for a user. Returns QR code URL and secret for TOTP, or sends a verification code for email.



## OpenAPI

````yaml /es/openapi/v3-current/AM-identity.yaml post /v1/users/{id}/mfa/setup
openapi: 3.0.1
info:
  contact: {}
  description: This is a swagger documentation for the Identity API
  termsOfService: http://swagger.io/terms/
  title: Identity API
  version: 1.0.0
servers:
  - url: //localhost:4001/
security: []
paths:
  /v1/users/{id}/mfa/setup:
    post:
      tags:
        - MFA
      summary: Initiate MFA Setup
      description: >-
        Initiates MFA setup for a user. Returns QR code URL and secret for TOTP,
        or sends a verification code for email.
      parameters:
        - description: User ID
          in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MFASetupInput'
        description: MFA Setup Input
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MFASetupResponse'
          description: OK
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/pkg.HTTPError'
          description: Bad Request
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/pkg.HTTPError'
          description: Not Found
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/pkg.HTTPError'
          description: Internal Server Error
      security:
        - BearerAuth: []
components:
  schemas:
    MFASetupInput:
      description: MFASetupInput payload
      example:
        mfaType: app
      properties:
        mfaType:
          description: 'MFA type: "app" (TOTP) or "email"'
          enum:
            - app
            - email
          example: app
          type: string
      required:
        - mfaType
      type: object
    MFASetupResponse:
      description: MFASetupResponse payload
      example:
        mfaType: app
        secret: JBSWY3DPEHPK3PXP
        enabled: true
        recoveryCodes:
          - recoveryCodes
          - recoveryCodes
        url: otpauth://totp/...
      properties:
        enabled:
          description: Whether MFA was already enabled
          type: boolean
        mfaType:
          description: Configured MFA type
          example: app
          type: string
        recoveryCodes:
          description: Recovery codes (store in a safe place)
          items:
            type: string
          type: array
        secret:
          description: Secret for manual TOTP configuration
          example: JBSWY3DPEHPK3PXP
          type: string
        url:
          description: otpauth URL for QR code (TOTP only)
          example: otpauth://totp/...
          type: string
      type: object
    pkg.HTTPError:
      properties:
        code:
          type: string
        entityType:
          type: string
        err:
          type: object
        message:
          type: string
        title:
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      description: 'Bearer authentication. Send Authorization: Bearer <token>.'
      in: header
      name: Authorization
      type: apiKey

````