Skip to main content
Client for Auth0 MFA API operations Manages multi-factor authentication including:
  • Listing enrolled authenticators
  • Enrolling new authenticators (OTP, SMS, Voice, Push, Email)
  • Initiating MFA challenges
  • Verifying MFA challenges
This is a wrapper around auth0-auth-js MfaClient that maintains backward compatibility with the existing spa-js API. MFA context (scope, audience) is stored internally keyed by mfaToken, enabling concurrent MFA flows without state conflicts.

Methods

challenge()

Initiates an MFA challenge Sends OTP via SMS, initiates push notification, or prepares for OTP entry

Parameters

ChallengeAuthenticatorParams
required
Challenge parameters including mfaTokenType: ChallengeAuthenticatorParams

Returns

Promise<ChallengeResponse> Challenge response with oobCode if applicable

enroll()

Enrolls a new MFA authenticator Requires MFA access token with ‘enroll’ scope

Parameters

EnrollParams
required
Enrollment parameters including mfaToken and factorTypeType: EnrollParams

Returns

Promise<EnrollmentResponse> Enrollment response with authenticator details

getAuthenticators()

Gets enrolled MFA authenticators filtered by challenge types from context. Challenge types are automatically resolved from the stored MFA context (set when mfa_required error occurred).

Parameters

string
required
MFA token from mfa_required error

Returns

Promise<Authenticator[]> Array of enrolled authenticators matching the challenge types

getEnrollmentFactors()

Gets available MFA enrollment factors from the stored context. This method exposes the enrollment options from the mfa_required error’s mfaRequirements.enroll array, eliminating the need for manual parsing.

Parameters

string
required
MFA token from mfa_required error

Returns

Promise<EnrollmentFactor[]> Array of enrollment factors available for the user (empty array if no enrollment required)

verify()

Verifies an MFA challenge and completes authentication The scope and audience are retrieved from the stored context (set when the mfa_required error occurred). The grant_type is automatically inferred from which verification field is provided (otp, oobCode, or recoveryCode).

Parameters

VerifyParams
required
Verification parameters with OTP, OOB code, or recovery codeType: VerifyParams

Returns

Promise<TokenEndpointResponse> Token response with access_token, id_token, refresh_token