CompleteTwoFactorLoginRequest
What CompleteTwoFactorLoginAsync takes to finish a sign-in the second factor stopped. Validation only checks that both values are present; whether the challenge is still redeemable and whether the code verifies are decided by the service.
Fields
Challenge: string
The challenge LoginAsync handed back, submitted in the form it was returned rather than decoded or trimmed. It stands for a password that already verified, so post it in the body and keep it out of URLs and logs.
Code: string
The code from the authenticator app, or one of the recovery codes issued at enrolment. Both are tried, so nothing here says which was sent.
Type signature
csharp
public sealed record CompleteTwoFactorLoginRequest
{
public required string Challenge { get; set; }
public required string Code { get; set; }
}