openapi: 3.2.0 info: title: MyAccount Management Authenticators API version: 2025.01.1 description: 'APIs for managing a user''s own emails, phones, profile, and app authenticators. > **Note:** The MyAccount API doesn''t support delegated authentication.' termsOfService: https://developer.okta.com/terms/ contact: name: Okta Developer Team url: https://developer.okta.com/ email: devex-public@okta.com license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html x-logo: url: logo.svg backgroundColor: transparent altText: Okta Developer servers: - url: https://{yourOktaDomain} variables: yourOktaDomain: default: subdomain.okta.com description: The domain of your organization. This can be an official Okta domain (for example, `okta.com` or `oktapreview.com`) or one of your configured custom domains. tags: - name: Authenticators description: 'The MyAccount Authenticators API provides operations to list all available authenticators and enrollments. ### API versioning A valid API version in the `Accept` header is required to access the API. Current version: `1.0.0` ```json Accept: application/json; okta-version=1.0.0 ```' x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine paths: /idp/myaccount/authenticators: x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine get: summary: List all Authenticators description: Lists all of the authenticators for the current user operationId: listAuthenticators parameters: - $ref: '#/components/parameters/queryExpandAuthenticator' responses: '200': $ref: '#/components/responses/ListAuthenticatorsResponse' '403': $ref: '#/components/responses/ErrorAccessDenied403' '429': $ref: '#/components/responses/ErrorTooManyRequests429' security: - oauth2: - okta.myAccount.authenticators.read tags: - Authenticators /idp/myaccount/authenticators/{authenticatorId}: parameters: - $ref: '#/components/parameters/pathAuthenticatorId' get: summary: Retrieve an Authenticator description: Retrieves an authenticator by `authenticatorId` operationId: getAuthenticator parameters: - $ref: '#/components/parameters/queryExpandAuthenticator' responses: '200': $ref: '#/components/responses/AuthenticatorResponse' '403': $ref: '#/components/responses/ErrorAccessDenied403' '404': $ref: '#/components/responses/ErrorResourceNotFound404' '429': $ref: '#/components/responses/ErrorTooManyRequests429' security: - oauth2: - okta.myAccount.authenticators.read tags: - Authenticators x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine /idp/myaccount/authenticators/{authenticatorId}/enrollments: parameters: - $ref: '#/components/parameters/pathAuthenticatorId' get: summary: List all Enrollments description: Lists all enrollments the current user has for an authenticator operationId: listEnrollments responses: '200': $ref: '#/components/responses/ListEnrollmentsResponse' '403': $ref: '#/components/responses/ErrorAccessDenied403' '404': $ref: '#/components/responses/ErrorResourceNotFound404' '429': $ref: '#/components/responses/ErrorTooManyRequests429' security: - oauth2: - okta.myAccount.authenticators.read tags: - Authenticators x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine /idp/myaccount/authenticators/{authenticatorId}/enrollments/{enrollmentId}: parameters: - $ref: '#/components/parameters/pathAuthenticatorId' - $ref: '#/components/parameters/pathEnrollmentId' get: summary: Retrieve an Enrollment description: Retrieves an enrollment by `enrollmentId` operationId: getEnrollment responses: '200': $ref: '#/components/responses/EnrollmentResponse' '403': $ref: '#/components/responses/ErrorAccessDenied403' '404': $ref: '#/components/responses/ErrorResourceNotFound404' '429': $ref: '#/components/responses/ErrorTooManyRequests429' security: - oauth2: - okta.myAccount.authenticators.read tags: - Authenticators x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine patch: summary: Update an enrollment description: 'Updates an authenticator enrollment by `enrollmentId`. The following update operations are allowed: * Update the enrollment nickname * Remove the enrollment nickname' operationId: updateEnrollment requestBody: content: application/merge-patch+json;okta-version=1.0.0: schema: $ref: '#/components/schemas/UpdateAuthenticatorEnrollmentRequest' examples: UpdateAuthenticatorEnrollmentNicknameEx: $ref: '#/components/examples/UpdateAuthenticatorEnrollmentNicknameEx' RemoveAuthenticatorEnrollmentNicknameEx: $ref: '#/components/examples/RemoveAuthenticatorEnrollmentNicknameEx' responses: '200': description: OK content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/AuthenticatorEnrollment' '401': description: Unauthorized content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '403': description: Access Denied content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '404': description: Resource Not Found content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' security: - oauth2: - okta.myAccount.authenticators.manage tags: - Authenticators x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine components: examples: ListAuthenticatorsExample: summary: List all authenticators value: - id: aut3ji50IyerHHpCa0g5 key: okta_email name: Email enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idp/authenticators/setup/aut3ji50IyerHHpCa0g5 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5/enrollments hints: allow: - GET - id: aut3ji4zFcHpwBlic0g5 key: okta_password name: Password enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji4zFcHpwBlic0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idp/authenticators/setup/aut3ji4zFcHpwBlic0g5/enrollments hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji4zFcHpwBlic0g5/enrollments hints: allow: - GET - id: aut3jiaiZukD4Ta0Z0g5 key: webauthn name: Security Key or Biometric enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idp/authenticators/setup/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments hints: allow: - GET ListAuthenticatorsExpandExample: summary: List all authenticators with embedded enrollments using the `expand=enrollments` query parameter value: - id: aut3ji50IyerHHpCa0g5 key: okta_email name: Email enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idpauthenticators/setup/aut3ji50IyerHHpCa0g5 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5/enrollments hints: allow: - GET _embedded: enrollments: - id: eae3jiacDBMEjIC9V0g5 name: Email created: '2023-08-10T20:11:55.000Z' profile: email: s***q@example.com canUnenroll: true canReset: false links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5/enrollments/eae3jiacDBMEjIC9V0g5 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5 hints: allow: - GET unenroll: href: https://sampleorg.okta.com/idp/authenticators/aut3ji50IyerHHpCa0g5/unenroll hints: allow: - GET - id: aut3ji4zFcHpwBlic0g5 key: okta_password name: Password enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji4zFcHpwBlic0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idpauthenticators/setup/aut3ji4zFcHpwBlic0g5 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji4zFcHpwBlic0g5/enrollments hints: allow: - GET _embedded: enrollments: - id: lae9bw3rvnO03wAbx0g4 name: Password created: '2023-08-10T20:11:55.000Z' canUnenroll: false canReset: true links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji4zFcHpwBlic0g5/enrollments/lae9bw3rvnO03wAbx0g4 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji4zFcHpwBlic0g5 hints: allow: - GET modify: href: https://sampleorg.okta.com/idp/authenticators/aut3ji4zFcHpwBlic0g5/modify hints: allow: - GET - id: aut3jiaiZukD4Ta0Z0g5 key: webauthn name: Security Key or Biometric enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idp/authenticators/setup/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments hints: allow: - GET _embedded: enrollments: - id: fwf3jiatpzkqerFkA0g5 name: MacBook Touch ID created: '2023-08-10T20:12:01.000Z' canUnenroll: true canReset: false links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments/fwf3jiatpzkqerFkA0g5 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET unenroll: href: https://sampleorg.okta.com/idp/authenticators/aut3jiaiZukD4Ta0Z0g5/unenroll hints: allow: - GET - id: fwf3jiaukymSFdBBS0g5 name: YubiKey 5 created: '2023-08-10T20:12:03.000Z' canUnenroll: false canReset: false links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments/fwf3jiaukymSFdBBS0g5 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET ErrorAccessDenied: summary: Access Denied value: errorCode: E0000006 errorSummary: You don't have permission to perform the requested action. errorLink: E0000006 errorId: sampleNUSD_8fdkFd8fs8SDBK errorCauses: [] ListEnrollmentsExample: summary: All security key and biometric enrollments value: - id: fwf3jiatpzkqerFkA0g5 name: MacBook Touch ID created: '2023-08-10T20:12:01.000Z' canReset: false canUnenroll: true links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments/fwf3jiatpzkqerFkA0g5 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET unenroll: href: https://sampleorg.okta.com/idp/authenticators/aut3jiaiZukD4Ta0Z0g5/unenroll hints: allow: - GET - id: fwf3jiaukymSFdBBS0g5 name: YubiKey 5 created: '2023-08-10T20:12:03.000Z' canReset: false canUnenroll: true links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments/fwf3jiaukymSFdBBS0g5 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET unenroll: href: https://sampleorg.okta.com/idp/authenticators/aut3jiaiZukD4Ta0Z0g5/unenroll hints: allow: - GET AuthenticatorExampleSecurityKey: summary: Security key authenticator value: id: aut65i8bdXk90tyfr0q7 key: webauthn name: Security Key or Biometric enrollable: false _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut65i8bdXk90tyfr0q7 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut65i8bdXk90tyfr0q7/enrollments hints: allow: - GET EnrollmentExampleEmail: summary: Email enrollment value: id: eae3jiacDBMEjIC9V0g5 name: Email created: '2023-08-10T20:11:55.000Z' profile: email: s***q@example.com canReset: false canUnenroll: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5/enrollments/eae3jiacDBMEjIC9V0g5 hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3ji50IyerHHpCa0g5 hints: allow: - GET unenroll: href: https://sampleorg.okta.com/idp/authenticators/aut3ji50IyerHHpCa0g5/unenroll hints: allow: - GET RemoveAuthenticatorEnrollmentNicknameEx: summary: Remove authenticator enrollment nickname value: nickname: null ErrorResourceNotFound: summary: Resource Not Found value: errorCode: E0000007 errorSummary: 'Not found: {0}' errorLink: E0000007 errorId: sampleMlLvGUj_YD5v16vkYWY errorCauses: [] UpdateAuthenticatorEnrollmentNicknameEx: summary: Update authenticator enrollment nickname value: nickname: Bob's Phone AuthenticatorExamplePassword: summary: Password authenticator value: id: aut3jiaiZukD4Ta0Z0g5 key: okta_password name: Okta password enrollable: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET enroll: href: https://sampleorg.okta.com/idp/authenticators/setup/aut3jiaiZukD4Ta0Z0g5 hints: allow: - GET enrollments: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut3jiaiZukD4Ta0Z0g5/enrollments hints: allow: - GET EnrollmentExampleSecurityKey: summary: Security key enrollment value: id: fwf3jiaukymSFdBBS0g5 name: YubiKey 5 created: '2023-05-01T14:24:54.000Z' lastChallenged: '2023-06-01T13:44:54.000Z' canReset: false canUnenroll: true _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut7liEC2BWqGZ8tosym/enrollments/pasfs1tgsKqEha3JwZKq hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut7liEC2BWqGZ8tosym hints: allow: - GET unenroll: href: https://sampleorg.okta.com/idp/authenticators/aut7liEC2BWqGZ8tosym/unenroll hints: allow: - GET ErrorTooManyRequests: summary: Too Many Requests value: errorCode: E0000047 errorSummary: You exceeded the maximum number of requests. Try again in a while. errorLink: E0000047 errorId: sampleQPivGUj_ND5v78vbYWW errorCauses: [] EnrollmentExamplePassword: summary: Password enrollment value: id: pasfs1tgsKqEha3JwZKq name: Okta password created: '2023-05-01T14:24:54.000Z' lastChallenged: '2023-06-01T13:44:54.000Z' canReset: true canUnenroll: false _links: self: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut7liEC2BWqGZ8tosym/enrollments/pasfs1tgsKqEha3JwZKq hints: allow: - GET authenticator: href: https://sampleorg.okta.com/idp/myaccount/authenticators/aut7liEC2BWqGZ8tosym hints: allow: - GET modify: href: https://sampleorg.okta.com/idp/authenticators/aut7liEC2BWqGZ8tosym/modify hints: allow: - GET schemas: HttpMethod: type: string enum: - DELETE - GET - POST - PUT Error: description: Standard API error object type: object properties: errorCauses: type: array description: (Optional) Further information about what caused this error items: type: object properties: errorSummary: type: string description: A natural language explanation of the error example: Bad request because XYZ is missing. readOnly: true errorCode: type: string description: A code that is associated with this error type example: E0000001 readOnly: true errorId: type: string description: A unique identifier for this error. This can be used by Okta Support to help with troubleshooting. example: oaeWGQKoQHeQmy0u8w8bPwi_Q readOnly: true errorLink: type: string description: A link to documentation with a more detailed explanation of the error (not yet implemented and is currently the same value as the 'errorCode') example: E0000001 readOnly: true errorSummary: type: string description: A natural language explanation of the error example: Bad request because XYZ is missing. readOnly: true Authenticator: description: A specific authenticator of the current user type: object properties: enrollable: type: boolean readOnly: true id: type: string readOnly: true key: $ref: '#/components/schemas/AuthenticatorKey' name: type: string readOnly: true _embedded: type: object readOnly: true properties: enrollments: type: array items: $ref: '#/components/schemas/AuthenticatorEnrollment' _links: type: object readOnly: true properties: self: $ref: '#/components/schemas/HrefObject' enroll: $ref: '#/components/schemas/HrefObject' enrollments: $ref: '#/components/schemas/HrefObject' AuthenticatorKey: type: string enum: - custom_app - custom_otp - duo - external_idp - google_otp - okta_email - okta_password - okta_verify - onprem_mfa - phone_number - rsa_token - security_question - symantec_vip - webauthn - yubikey_token readOnly: true UpdateAuthenticatorEnrollmentRequest: type: object properties: nickname: type: string HrefObject: title: Link object type: object properties: hints: type: object description: Describes allowed HTTP verbs for the `href` properties: allow: type: array items: $ref: '#/components/schemas/HttpMethod' href: type: string description: Link URI name: type: string description: Link name type: type: string description: The media type of the link. If omitted, it is implicitly `application/json`. required: - href readOnly: true AuthenticatorEnrollment: description: Authenticator enrollment of the current user type: object properties: canReset: type: boolean readOnly: true canUnenroll: type: boolean readOnly: true created: type: string readOnly: true id: type: string readOnly: true lastChallenged: type: string readOnly: true name: type: string nickname: type: string profile: type: object readOnly: true _links: type: object readOnly: true properties: self: $ref: '#/components/schemas/HrefObject' authenticator: $ref: '#/components/schemas/HrefObject' modify: $ref: '#/components/schemas/HrefObject' unenroll: $ref: '#/components/schemas/HrefObject' responses: AuthenticatorResponse: description: Authenticator content: application/json: schema: $ref: '#/components/schemas/Authenticator' examples: AuthenticatorExamplePassword: $ref: '#/components/examples/AuthenticatorExamplePassword' AuthenticatorExampleSecurityKey: $ref: '#/components/examples/AuthenticatorExampleSecurityKey' ListAuthenticatorsResponse: description: Authenticators content: application/json: schema: type: array items: $ref: '#/components/schemas/Authenticator' examples: ListAuthenticatorsExample: $ref: '#/components/examples/ListAuthenticatorsExample' ListAuthenticatorsExpandExample: $ref: '#/components/examples/ListAuthenticatorsExpandExample' ErrorAccessDenied403: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/Error' examples: AccessDenied: $ref: '#/components/examples/ErrorAccessDenied' ListEnrollmentsResponse: description: Enrollments content: application/json: schema: type: array items: $ref: '#/components/schemas/AuthenticatorEnrollment' examples: ListEnrollmentsExample: $ref: '#/components/examples/ListEnrollmentsExample' ErrorResourceNotFound404: description: Not Found content: application/json: schema: $ref: '#/components/schemas/Error' examples: ResourceNotFound: $ref: '#/components/examples/ErrorResourceNotFound' ErrorTooManyRequests429: description: Too Many Requests content: application/json: schema: $ref: '#/components/schemas/Error' examples: TooManyRequests: $ref: '#/components/examples/ErrorTooManyRequests' EnrollmentResponse: description: Enrollment content: application/json: schema: $ref: '#/components/schemas/AuthenticatorEnrollment' examples: EnrollmentExamplePassword: $ref: '#/components/examples/EnrollmentExamplePassword' EnrollmentExampleEmail: $ref: '#/components/examples/EnrollmentExampleEmail' EnrollmentExampleSecurityKey: $ref: '#/components/examples/EnrollmentExampleSecurityKey' parameters: queryExpandAuthenticator: name: expand in: query description: Optional additional items to return in the `_embedded` object. Currently supports the value `enrollments`. schema: type: string example: enrollments pathEnrollmentId: name: enrollmentId in: path required: true description: '`id` of the authenticator enrollment' schema: type: string example: ufs2bysphxKODSZKWVCT pathAuthenticatorId: name: authenticatorId in: path required: true description: '`id` of the authenticator' schema: type: string example: aut9gnvcjUHIWb37J0g4 securitySchemes: oauth2: type: oauth2 description: 'Pass the access_token as the value of the Authorization header: `Authorization: Bearer {access_token}`' flows: authorizationCode: authorizationUrl: /oauth2/v1/authorize tokenUrl: /oauth2/v1/token scopes: okta.myAccount.appAuthenticator.maintenance.manage: Write access to non-sensitive attributes of user app authenticator enrollments okta.myAccount.appAuthenticator.maintenance.read: Read access to non-sensitive attributes of user app authenticator enrollments okta.myAccount.appAuthenticator.manage: Write access to user app authenticator enrollments okta.myAccount.appAuthenticator.read: Read access to user app authenticator enrollments okta.myAccount.authenticators.manage: Write access to user authenticator enrollments okta.myAccount.authenticators.read: Read access to user authenticator configurations and enrollments okta.myAccount.email.manage: Write access to user emails okta.myAccount.email.read: Read access to user emails okta.myAccount.oktaApplications.read: Read access to the Okta apps list okta.myAccount.organization.read: Read access to org details okta.myAccount.password.manage: Write access to user password okta.myAccount.password.read: Read access to user password metadata okta.myAccount.phone.manage: Write access to user phones okta.myAccount.phone.read: Read access to user phones okta.myAccount.profile.manage: Write access to user profile and schema okta.myAccount.profile.read: Read access to user profile and schema okta.myAccount.sessions.manage: Write access to user sessions externalDocs: description: Find more info here url: https://developer.okta.com