> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging-feat-sdk-reference-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# MfaApiClient

> Client for Auth0 MFA API operations Manages multi-factor authentication including: - Listing enrolled authenticators - Enrolling new authenticators (OTP, SMS, …

Client for Auth0 MFA API operations

Manages multi-factor authentication including:

* Listing enrolled authenticators
* Enrolling new authenticators (OTP, SMS, Voice, Push, Email)
* Initiating MFA challenges
* Verifying MFA challenges

This is a wrapper around auth0-auth-js MfaClient that maintains
backward compatibility with the existing spa-js API.

MFA context (scope, audience) is stored internally keyed by mfaToken,
enabling concurrent MFA flows without state conflicts.

```typescript
try {
  await auth0.getTokenSilently({ authorizationParams: { audience: 'https://api.example.com' } });
} catch (e) {
  if (e instanceof MfaRequiredError) {
    // SDK automatically stores context for this mfaToken
    const authenticators = await auth0.mfa.getAuthenticators({ mfaToken: e.mfa_token });
    // ... complete MFA flow
  }
}
```

## Methods

### challenge()

```typescript
challenge(params: ChallengeAuthenticatorParams): Promise<ChallengeResponse>
```

Initiates an MFA challenge

Sends OTP via SMS, initiates push notification, or prepares for OTP entry

```typescript
const challenge = await mfa.challenge({
  mfaToken: mfaTokenFromLogin,
  challengeType: 'otp',
  authenticatorId: 'otp|dev_xxx'
});
// User enters OTP from their authenticator app
```

#### Parameters

<ResponseField name={"params"} type={"ChallengeAuthenticatorParams"} required>
  Challenge parameters including mfaToken

  Type: [ChallengeAuthenticatorParams](/docs/sdk/typescript/interfaces/ChallengeAuthenticatorParams)
</ResponseField>

#### Returns

`Promise<ChallengeResponse>`

Challenge response with oobCode if applicable

### enroll()

```typescript
enroll(params: EnrollParams): Promise<EnrollmentResponse>
```

Enrolls a new MFA authenticator

Requires MFA access token with 'enroll' scope

```typescript
const enrollment = await mfa.enroll({
  mfaToken: mfaToken,
  factorType: 'otp'
});
console.log(enrollment.secret); // Base32 secret
console.log(enrollment.barcodeUri); // QR code URI
```

#### Parameters

<ResponseField name={"params"} type={"EnrollParams"} required>
  Enrollment parameters including mfaToken and factorType

  Type: [EnrollParams](/docs/sdk/typescript/types/EnrollParams)
</ResponseField>

#### Returns

`Promise<EnrollmentResponse>`

Enrollment response with authenticator details

### getAuthenticators()

```typescript
getAuthenticators(mfaToken: string): Promise<Authenticator[]>
```

Gets enrolled MFA authenticators filtered by challenge types from context.

Challenge types are automatically resolved from the stored MFA context
(set when mfa\_required error occurred).

```typescript
try {
  await auth0.getTokenSilently();
} catch (e) {
  if (e instanceof MfaRequiredError) {
    // SDK automatically uses challenge types from error context
    const authenticators = await auth0.mfa.getAuthenticators(e.mfa_token);
  }
}
```

#### Parameters

<ResponseField name={"mfaToken"} type={"string"} required>
  MFA token from mfa\_required error
</ResponseField>

#### Returns

`Promise<Authenticator[]>`

Array of enrolled authenticators matching the challenge types

### getEnrollmentFactors()

```typescript
getEnrollmentFactors(mfaToken: string): Promise<EnrollmentFactor[]>
```

Gets available MFA enrollment factors from the stored context.

This method exposes the enrollment options from the mfa\_required error's
mfaRequirements.enroll array, eliminating the need for manual parsing.

```typescript
try {
  await auth0.getTokenSilently();
} catch (error) {
  if (error.error === 'mfa_required') {
    // Get enrollment options from SDK
    const enrollOptions = await auth0.mfa.getEnrollmentFactors(error.mfa_token);
    // [{ type: 'otp' }, { type: 'phone' }, { type: 'push-notification' }]

    showEnrollmentOptions(enrollOptions);
  }
}
```

#### Parameters

<ResponseField name={"mfaToken"} type={"string"} required>
  MFA token from mfa\_required error
</ResponseField>

#### Returns

`Promise<EnrollmentFactor[]>`

Array of enrollment factors available for the user (empty array if no enrollment required)

### verify()

```typescript
verify(params: VerifyParams): Promise<TokenEndpointResponse>
```

Verifies an MFA challenge and completes authentication

The scope and audience are retrieved from the stored context (set when the
mfa\_required error occurred). The grant\_type is automatically inferred from
which verification field is provided (otp, oobCode, or recoveryCode).

```typescript
const tokens = await mfa.verify({
  mfaToken: mfaTokenFromLogin,
  otp: '123456'
});
console.log(tokens.access_token);
```

#### Parameters

<ResponseField name={"params"} type={"VerifyParams"} required>
  Verification parameters with OTP, OOB code, or recovery code

  Type: [VerifyParams](/docs/sdk/typescript/interfaces/VerifyParams)
</ResponseField>

#### Returns

`Promise<TokenEndpointResponse>`

Token response with access\_token, id\_token, refresh\_token
