> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://en.megaport.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://en.megaport.ferndocs.com/_mcp/server.

# Reset Person Multi-Factor Authentication

PUT https://api.megaport.com/v2/employee/{employeeId}/mfa
Content-Type: application/json

Resets Multi-Factor Authentication (MFA) for a user.

This is equivalent to resetting MFA for a user from the User Profile option under the user's name in the Megaport Portal. For more information, see [Managing Your User Profile](https://docs.megaport.com/setting-up/manage-profile/).

You can find the employee ID (`personId`) using the GET List Company Users `/v2/employment` endpoint.

When MFA is enabled for a user, it can be reset to enroll a new mobile device. You can reset MFA for a user regardless of the global MFA setting for your company. That is, whether MFA has been set to enforced or optional by a Company Admin for your company.

**Note:**

- The user will remain logged in to the Megaport Portal when resetting MFA.
- Resetting MFA does not disable MFA for the user account.
- Megaport Support is unable to reset or regenerate QR codes for customers. A Company Admin must perform this task in the Megaport Portal.
    

Changes are defined in the Body of the request. The attributes have these values.

- `totpSecret` - (Required - string) A secret returned by calling the `/v2/totp/qrcode` endpoint. It has a length of 16 characters and contains only capital letters and digits.
- `totpCode` - (Required - string) A 6-digit number generated based on totpSecret. The user can scan the QR code with apps like Google authenticator and that app will generate the code for the user.
    

For more information, see [Enforcing Multi-Factor Authentication](https://docs.megaport.com/setting-up/enforcing-mfa/).

Reference: https://en.megaport.ferndocs.com/api-reference/user-authentication/reset-person-multi-factor-authentication

## Servers

- `https://api.megaport.com` (Production environment, default)
- `https://api-staging.megaport.com` (Staging environment (test only, reset every 24 hours))

## Request

### Path parameters

- `employeeId` (string, required)

### Body (application/json)

This endpoint expects an object.

- `totpCode` (string, optional)
- `totpSecret` (string, optional)

## Response

### 200

Reset Person Multi-Factor Authentication - Success / Reset Person Multi-Factor Authentication - Success

- `message` (string, optional)
- `terms` (string, optional)

## Errors

### 400 Bad Request Error

Reset Person Multi-Factor Authentication - OTP Missing or Invalid / Reset Person Multi-Factor Authentication - OTP Missing or Invalid

- `message` (string, optional)
- `terms` (string, optional)

### 401 Unauthorized Error

Reset Person Multi-Factor Authentication - Token Issue / Reset Person Multi-Factor Authentication - Token Issue

- `message` (string, optional)
- `terms` (string, optional)

### 403 Forbidden Error

Reset Person Multi-Factor Authentication - New OTP Secret Identical / Reset Person Multi-Factor Authentication - New OTP Secret Identical

- `message` (string, optional)
- `terms` (string, optional)

### 404 Not Found Error

Reset Person Multi-Factor Authentication - User Not Found / Reset Person Multi-Factor Authentication - User Not Found

- `message` (string, optional)
- `terms` (string, optional)

## Examples

### Reset Person Multi-Factor Authentication - Success

**Response**

```json
{
  "message": "Your MFA has been reset successfully",
  "terms": "This data is subject to the Acceptable Use Policy https://www.megaport.com/legal/acceptable-use-policy"
}
```

**SDK Code**

```python Reset Person Multi-Factor Authentication - Success
import requests

url = "https://api.megaport.com/v2/employee/employeeId/mfa"

response = requests.put(url)

print(response.json())
```

```javascript Reset Person Multi-Factor Authentication - Success
const url = 'https://api.megaport.com/v2/employee/employeeId/mfa';
const options = {method: 'PUT'};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Reset Person Multi-Factor Authentication - Success
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.megaport.com/v2/employee/employeeId/mfa"

	req, _ := http.NewRequest("PUT", url, nil)

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Reset Person Multi-Factor Authentication - Success
require 'uri'
require 'net/http'

url = URI("https://api.megaport.com/v2/employee/employeeId/mfa")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Put.new(url)

response = http.request(request)
puts response.read_body
```

```java Reset Person Multi-Factor Authentication - Success
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.put("https://api.megaport.com/v2/employee/employeeId/mfa")
  .asString();
```

```php Reset Person Multi-Factor Authentication - Success
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.megaport.com/v2/employee/employeeId/mfa');

echo $response->getBody();
```

```csharp Reset Person Multi-Factor Authentication - Success
using RestSharp;

var client = new RestClient("https://api.megaport.com/v2/employee/employeeId/mfa");
var request = new RestRequest(Method.PUT);
IRestResponse response = client.Execute(request);
```

```swift Reset Person Multi-Factor Authentication - Success
import Foundation

let request = NSMutableURLRequest(url: NSURL(string: "https://api.megaport.com/v2/employee/employeeId/mfa")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PUT"

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Reset Person Multi-Factor Authentication

**Request**

```json
{
  "totpCode": "123456",
  "totpSecret": "G4C3S6MBH2HSF2EV"
}
```

**Response**

```json
{
  "message": "Your MFA has been reset successfully",
  "terms": "This data is subject to the Acceptable Use Policy https://www.megaport.com/legal/acceptable-use-policy"
}
```

**SDK Code**

```python Reset Person Multi-Factor Authentication
import requests

url = "https://api.megaport.com/v2/employee/employeeId/mfa"

payload = {
    "totpCode": "123456",
    "totpSecret": "G4C3S6MBH2HSF2EV"
}
headers = {"Content-Type": "application/json"}

response = requests.put(url, json=payload, headers=headers)

print(response.json())
```

```javascript Reset Person Multi-Factor Authentication
const url = 'https://api.megaport.com/v2/employee/employeeId/mfa';
const options = {
  method: 'PUT',
  headers: {'Content-Type': 'application/json'},
  body: '{"totpCode":"123456","totpSecret":"G4C3S6MBH2HSF2EV"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Reset Person Multi-Factor Authentication
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.megaport.com/v2/employee/employeeId/mfa"

	payload := strings.NewReader("{\n  \"totpCode\": \"123456\",\n  \"totpSecret\": \"G4C3S6MBH2HSF2EV\"\n}")

	req, _ := http.NewRequest("PUT", url, payload)

	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Reset Person Multi-Factor Authentication
require 'uri'
require 'net/http'

url = URI("https://api.megaport.com/v2/employee/employeeId/mfa")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Put.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n  \"totpCode\": \"123456\",\n  \"totpSecret\": \"G4C3S6MBH2HSF2EV\"\n}"

response = http.request(request)
puts response.read_body
```

```java Reset Person Multi-Factor Authentication
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.put("https://api.megaport.com/v2/employee/employeeId/mfa")
  .header("Content-Type", "application/json")
  .body("{\n  \"totpCode\": \"123456\",\n  \"totpSecret\": \"G4C3S6MBH2HSF2EV\"\n}")
  .asString();
```

```php Reset Person Multi-Factor Authentication
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.megaport.com/v2/employee/employeeId/mfa', [
  'body' => '{
  "totpCode": "123456",
  "totpSecret": "G4C3S6MBH2HSF2EV"
}',
  'headers' => [
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp Reset Person Multi-Factor Authentication
using RestSharp;

var client = new RestClient("https://api.megaport.com/v2/employee/employeeId/mfa");
var request = new RestRequest(Method.PUT);
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"totpCode\": \"123456\",\n  \"totpSecret\": \"G4C3S6MBH2HSF2EV\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Reset Person Multi-Factor Authentication
import Foundation

let headers = ["Content-Type": "application/json"]
let parameters = [
  "totpCode": "123456",
  "totpSecret": "G4C3S6MBH2HSF2EV"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.megaport.com/v2/employee/employeeId/mfa")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PUT"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```