> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Request an MFA disable confirmation code

> Mails a 6-digit confirmation code to the member's account e-mail, for the disables that are proven by e-mail: `DELETE /v1/users/{id}/mfa/email`, and `DELETE /v1/users/{id}/mfa` when e-mail is the factor that proves it. Only a member with the `email` channel enabled is sent one.

The authenticator channel needs NO challenge — `DELETE /v1/users/{id}/mfa/app` is proven by the current passcode from the member's authenticator app — and a legacy `sms` clear needs no code at all. There is no request body: the destination is the address already on the account, never one the caller supplies.

Self-service only; `{id}` must be the caller's own user id. Sends are budgeted per member.

On success the response has no body (204).

Failures:
- `400 IDE-0041` — MFA is not enabled on the account.
- `400 IDE-0048` — the account has no e-mail to send to.
- `400 IDE-0049` — no disable on this account is proven by a mailed code: the `email` channel is not enabled (for example, an authenticator-only member, whatever their preference).
- `400 IDE-0045` — the code could not be sent or the challenge could not be recorded.
- `400 IDE-0062` — the send budget for the current window is spent; wait before asking again.
- `404 IDE-0013` — `{id}` is not the token's subject.
- `404` — no such user.
- `500` — only when the identity provider could not be reached.



## OpenAPI

````yaml /pt/openapi/v3-current/AM-identity.yaml post /v1/users/{id}/mfa/disable/challenge
openapi: 3.1.0
info:
  contact:
    name: Lerian Studio
    url: https://lerian.studio
  description: OpenAPI 3.1 surface for the Access Manager identity component.
  license:
    name: Lerian Studio General License
  title: Plugin Access Manager — Identity API
  version: v1
servers: []
security: []
tags:
  - description: >-
      M2M-only: each plugin declares its own permissions, roles and M2M
      contract, and the server reconciles them.
    name: Declarations
paths:
  /v1/users/{id}/mfa/disable/challenge:
    post:
      tags:
        - MFA
      summary: Request an MFA disable confirmation code
      description: >-
        Mails a 6-digit confirmation code to the member's account e-mail, for
        the disables that are proven by e-mail: `DELETE
        /v1/users/{id}/mfa/email`, and `DELETE /v1/users/{id}/mfa` when e-mail
        is the factor that proves it. Only a member with the `email` channel
        enabled is sent one.


        The authenticator channel needs NO challenge — `DELETE
        /v1/users/{id}/mfa/app` is proven by the current passcode from the
        member's authenticator app — and a legacy `sms` clear needs no code at
        all. There is no request body: the destination is the address already on
        the account, never one the caller supplies.


        Self-service only; `{id}` must be the caller's own user id. Sends are
        budgeted per member.


        On success the response has no body (204).


        Failures:

        - `400 IDE-0041` — MFA is not enabled on the account.

        - `400 IDE-0048` — the account has no e-mail to send to.

        - `400 IDE-0049` — no disable on this account is proven by a mailed
        code: the `email` channel is not enabled (for example, an
        authenticator-only member, whatever their preference).

        - `400 IDE-0045` — the code could not be sent or the challenge could not
        be recorded.

        - `400 IDE-0062` — the send budget for the current window is spent; wait
        before asking again.

        - `404 IDE-0013` — `{id}` is not the token's subject.

        - `404` — no such user.

        - `500` — only when the identity provider could not be reached.
      operationId: initiateMFADisableChallenge
      parameters:
        - description: User ID.
          in: path
          name: id
          required: true
          schema:
            description: User ID.
            examples:
              - 00000000-0000-0000-0000-000000000000
            type: string
      responses:
        '204':
          description: No Content
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Unauthorized
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Not Found
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Internal Server Error
      security:
        - BearerAuth: []
components:
  schemas:
    HTTPError:
      additionalProperties: false
      properties:
        code:
          type: string
        entityType:
          type: string
        err: {}
        message:
          type: string
        title:
          type: string
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.