curl --request PUT \
--url https://api.pomerado.ai/v1/logins/{id}/recovery-codes \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"codes": [
"<string>"
]
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({codes: ['<string>']})
};
fetch('https://api.pomerado.ai/v1/logins/{id}/recovery-codes', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/logins/{id}/recovery-codes"
payload = { "codes": ["<string>"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"id": "login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"label": "<string>",
"site": {
"url": "<string>",
"name": "<string>"
},
"username_masked": "<string>",
"identifier_type": "username",
"sign_in": "password",
"saved_fields": [
"email"
],
"two_factor": {
"authenticator": true,
"sms_number": "none"
},
"status": "unverified",
"needs_attention": {
"field": "username"
},
"locked": true,
"created_at": "<string>",
"updated_at": "<string>",
"verified_at": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Replace a login's recovery codes
Save a login’s two-factor recovery codes, replacing those it holds, since a website that issues new codes voids the old ones. They are never shown again, only counted. The codes pass through this client and its model provider: warn the user first.
curl --request PUT \
--url https://api.pomerado.ai/v1/logins/{id}/recovery-codes \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"codes": [
"<string>"
]
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({codes: ['<string>']})
};
fetch('https://api.pomerado.ai/v1/logins/{id}/recovery-codes', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/logins/{id}/recovery-codes"
payload = { "codes": ["<string>"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"id": "login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"label": "<string>",
"site": {
"url": "<string>",
"name": "<string>"
},
"username_masked": "<string>",
"identifier_type": "username",
"sign_in": "password",
"saved_fields": [
"email"
],
"two_factor": {
"authenticator": true,
"sms_number": "none"
},
"status": "unverified",
"needs_attention": {
"field": "username"
},
"locked": true,
"created_at": "<string>",
"updated_at": "<string>",
"verified_at": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Authorization: Bearer <token> with Dashboard session, Pomerado MCP OAuth token, API key.
Permission: logins:manage.
Effect: Write: creates or changes something in your account.
Errors: invalid_request (400), unauthorized (401), reauthentication_required (401), forbidden (403), not_found (404), site_login_exists (409), login_identity_conflict (409), legacy_duplicate_saved_logins (409), saved_login_unsettled (409), login_in_use (409), login_save_in_progress (409), request_too_large (413), invalid_credential (422), internal_error (500), acceptance_unknown (503), temporarily_unavailable (503). Every error has the same envelope.Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
a saved login ID: login_ and 32 lowercase hex digits
"login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
Body
an array of at most 20 item(s)
1 - 20 elementsa string at most 64 character(s) long
4 - 64Response
The login
a saved login ID: login_ and 32 lowercase hex digits
"login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
Show child attributes
Show child attributes
username, email, phone, account_number password, code What it holds besides its username and password; null when not recorded
email, phone, account_number, date_of_birth, zip, recovery_codes, preferred_method Show child attributes
Show child attributes
unverified, verified, needs_attention Show child attributes
Show child attributes
When it was saved, ISO 8601 UTC
When it last changed, ISO 8601 UTC
Its first verified sign-in, ISO 8601 UTC; null before one