Repository navigation
feat: support two-factor sign-in for API clients with a signed token - #154
Draft
RenzoMinelli wants to merge 1 commit into
Draft
RenzoMinelli wants to merge 1 commit into
RenzoMinelli wants to merge 1 commit into
Conversation
RenzoMinelli
force-pushed
the
rm--api-two-factor
branch
from
September 25, 2026 18:48
28fc4ff to
0a73e6c
Compare
RenzoMinelli
marked this pull request as draft
September 25, 2026 19:04
RenzoMinelli
force-pushed
the
rm--api-two-factor
branch
from
September 25, 2026 19:30
0a73e6c to
ad65278
Compare
RenzoMinelli
force-pushed
the
rm--api-two-factor
branch
from
September 25, 2026 20:26
ad65278 to
74b2141
Compare
RenzoMinelli
force-pushed
the
rm--api-two-factor
branch
from
September 25, 2026 20:47
74b2141 to
dcaec83
Compare
RenzoMinelli
added this pull request to stack #156
October 2, 2026 20:17
RenzoMinelli
force-pushed
the
rm--api-two-factor
branch
from
October 3, 2026 02:11
dcaec83 to
c7da461
Compare
When a password sign-in needs a second factor and the request is not navigational, respond `401` with a `two_factor_token`. The security key options and two-factor endpoints accept it in place of the session. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
RenzoMinelli
force-pushed
the
rm--api-two-factor
branch
from
October 6, 2026 12:29
c7da461 to
691d172
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What: When a password sign-in needs a second factor and the request isn't navigational, respond
401with a signedtwo_factor_token. The security key options and two-factor endpoints accept it in place of the session. Browsers keep the session flow.Why: Without it, password sign-in breaks for API users who have a passkey or security key. Stacked on #153.
How to test:
bundle exec rspec spec/requests/devise/api_client_spec.rb, the "two-factor sign-in" examples.