Update optional 2FA users

Replaces the complete list of users for whom two-factor authentication (2FA) is optional. Users on this list can disable 2FA in their profiles even when the account-level enforcement policy requires it.

This list only takes effect when account-level enforcement is on. Run Update account settings with tfa_enforced: true to enforce 2FA.

Changes apply immediately. Users you remove from the optional list who haven't configured 2FA can't log in until they set it up.

This operation fully replaces the entire data object. Any username you omit reverts to the account-level policy. Pass an empty usernames array to remove all exemptions.

The 200 response returns a count, not the full updated list. To confirm what you saved, run List 2FA optional users.

📘

This operation has a specific rate limit.

Permissions and scopes

To call this operation, you need the following:

  • Identity and access permissions. Your user needs a role with these permissions assigned. Learn more.

    • Permissions: update_tfa_optional_users
  • OAuth scopes. Your user needs these scopes assigned. Learn more.

    • Scopes: account:read_write
Path Params
string
enum
required

Enum Call either the v4 URL, or v4beta for operations still in Beta.

Allowed:
Body Params

The request data to modify which users can optionally use two-factor authentication (2FA) regardless of the account-level policy.

usernames
array of strings
required
length ≥ 0

The usernames of account users for whom 2FA is optional. This replaces the current list entirely. Users not included here revert to the account-level enforcement policy. To get available usernames run List users. Pass an empty array to remove all exemptions.

usernames*
Responses

Language
Credentials
LoadingLoading…
Response
Choose an example:
application/json