How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Gremlin users.auth.mfa API

Endpoints for multi-factor user auth (MFA) and for managing MFA providers and secrets

Gremlin users.auth.mfa API is one of 55 APIs that Gremlin publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 1 JSON Schema definition.

The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and 1 JSON Schema.

This API exposes 7 operations across 7 paths, and defines 2 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, https://api.gremlin.com/v1.

7 operations 7 paths 2 schemas 2 GET5 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.gremlin.com/v1
Terms of Service
Resource Areas
1

Paths & Operations 7

Across 7 paths, the API surfaces 7 operations — 2 GET, 5 POST. Each is listed below with its method, path, parameters, and response codes.

users.auth.mfa 7

Endpoints for multi-factor user auth (MFA) and for managing MFA providers and secrets

POST
/users/auth/mfa/auth
Authenticate a user with MFA.
auth 1 param body → default403
POST
/users/auth/mfa/disable
Removes the MFA provider and secret, disabling MFA login.
disable body → default403
POST
/users/auth/mfa/enable
Generate a secret key and enables it for the user.
enable body → default403
POST
/users/auth/mfa/forceDisable
Removes the MFA provider and secret, disabling MFA login.
forceDisable body → default403401
GET
/users/auth/mfa/info
Returns the enabled/disabled status and provider if set, of MFA for the user.
getInfo → default403401
GET
/users/auth/mfa/{email}/enabled
Returns the enabled/disabled status of MFA for a user.
isEnabled 1 param → default403401
POST
/users/auth/mfa/validate
Validate a MFA token for a user
validate body → default403

Schemas 2

The contract defines 2 schemas that model the data the API accepts and returns. The most detailed are MfaEnableResponse (2 properties), MfaInfoResponse (2 properties). Each schema is shown below with its type and property counts.

MfaInfoResponse
object
2 properties
MfaEnableResponse
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

gremlin-users-auth-mfa-api-openapi.yml Raw ↑

Other APIs Gremlin publishes across the network.

Gremlin agents API
Gremlin apikeys API
Gremlin attacks API
Gremlin aws.metadata API
Gremlin clients API
Gremlin companies API
Gremlin containers API
Gremlin datadog API
Gremlin disaster-recovery-test-reports API
Gremlin disaster-recovery-tests API
Gremlin executions API
Gremlin external-integrations API
Where this information came from

This is an independent, third-party profile of Gremlin users.auth.mfa API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.