Skip to content

Start setting up an authenticator

POST
/storefront/sites/{host}/account/two-factor/setup
curl --request POST \
--url https://example.com/storefront/sites/northgate.shop.getbottle.app/account/two-factor/setup

Deliberately without a staff session: a shopper on the business’s own shop. A new secret, and the otpauth address to show as a QR code. Not on until POST two-factor/enable with a code from it.

host
required
string
Example
northgate.shop.getbottle.app

The secret

Media typeapplication/json
object
secret
required
string
otpauthUrl
required
string
Examplegenerated
{
"secret": "example",
"otpauthUrl": "example"
}

Refused: the message says why

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Not signed in

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Not from the shop itself, or the email is not confirmed yet

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Not a shop. No body.

A real shop not selling now (shop_closed)

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Validation failed

Media typeapplication/json
object
error
required
string
Allowed values: validation
message
required
string
issues
required
Array<object>
object
path
required
string
message
required
string
Example
{
"error": "validation",
"issues": [
{
"path": "email",
"message": "Invalid email"
}
]
}

Too many tries

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}