Request an MFA disable confirmation code
Mails a 6-digit confirmation code to the member’s account e-mail, for the disables that are proven by e-mail: DELETE /v1/users/{id}/mfa/email, and DELETE /v1/users/{id}/mfa when e-mail is the factor that proves it. Only a member with the email channel enabled is sent one.
The authenticator channel needs NO challenge — DELETE /v1/users/{id}/mfa/app is proven by the current passcode from the member’s authenticator app — and a legacy sms clear needs no code at all. There is no request body: the destination is the address already on the account, never one the caller supplies.
Self-service only; {id} must be the caller’s own user id. Sends are budgeted per member.
On success the response has no body (204).
Failures:
400 IDE-0041— MFA is not enabled on the account.400 IDE-0048— the account has no e-mail to send to.400 IDE-0049— no disable on this account is proven by a mailed code: theemailchannel is not enabled (for example, an authenticator-only member, whatever their preference).400 IDE-0045— the code could not be sent or the challenge could not be recorded.400 IDE-0062— the send budget for the current window is spent; wait before asking again.404 IDE-0013—{id}is not the token’s subject.404— no such user.500— only when the identity provider could not be reached.

