Skip to content

feat: support two-factor sign-in for API clients with a signed token - #154

Draft
RenzoMinelli wants to merge 1 commit into
rm--api-json-responsesfrom
rm--api-two-factor
Draft

RenzoMinelli wants to merge 1 commit into
rm--api-json-responsesfrom
rm--api-two-factor

Conversation

@RenzoMinelli

@RenzoMinelli RenzoMinelli commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

What: When a password sign-in needs a second factor and the request isn't navigational, respond 401 with a signed two_factor_token. The security key options and two-factor endpoints accept it in place of the session. Browsers keep the session flow.

Why: Without it, password sign-in breaks for API users who have a passkey or security key. Stacked on #153.

How to test: bundle exec rspec spec/requests/devise/api_client_spec.rb, the "two-factor sign-in" examples.

When a password sign-in needs a second factor and the request is not
navigational, respond `401` with a `two_factor_token`. The security key
options and two-factor endpoints accept it in place of the session.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant