> ## Documentation Index
> Fetch the complete documentation index at: https://docs.liftx.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify fresh authentication

> Proof has exactly one of password or apple_token, with mfa_code when required.

<Note>Preview contract. Production availability remains subject to activation and release qualification. Examples are synthetic; the documentation cannot submit requests.</Note>

## Authorization

Same authenticated Settings session and pending operation.

## Behavior

Proof has exactly one of password or apple\_token, with mfa\_code when required. Apple proof must match the nonce/audience and already-linked subject. The approval is purpose/payload-bound and consumed once during issuance. Five proof attempts share the approval budget.

This is a session-owned application contract, not an ordinary API-key endpoint. Use [Settings → Integrations](https://app.liftx.io/settings/integrations). The public API base URL does not grant session access.

## JSON body example

The following shows the request shape, not live credentials or executable market defaults. Replace timestamps only when creating a new reviewed intent; never mutate them on a command retry.

```json theme={null}
{
  "operation_id": "66666666-6666-4666-8666-666666666666",
  "proof": {
    "password": "PRIVATE_PASSWORD_FROM_AUTHENTICATED_SETTINGS",
    "mfa_code": "000000"
  }
}
```

The displayed password and MFA value are nonfunctional placeholders. Never store real account authentication proof in source code, public documentation or an integration client. This payload is sent only by the authenticated Settings flow.

## Response and errors

The generated response schema below is the wire contract. Preserve fixed-point strings, nullable fields and endpoint-specific envelopes. Inspect HTTP status and Content-Type before decoding failures; reused trading routes may return JSON or plain text. Authentication, entitlement and exact link/instrument restrictions apply in addition to endpoint validation. See [errors and recovery](/api/errors-and-limits).

Do not automatically repeat a mutation after transport ambiguity. Trading commands reuse the exact immutable identity; credential issuance and template writes require their documented metadata/read reconciliation.

Read the [related guide](/api/settings-contract) for lifecycle, units and recovery semantics.


## OpenAPI

````yaml api/openapi.json POST /integrations/reauth/verify
openapi: 3.1.0
info:
  title: Liftx integrations
  version: 1.0.0
  description: >-
    Preview contract for the Liftx API, TradingView webhook and session-owned
    integration settings. Production availability is pending activation and
    release qualification. External access requires Pro or trial entitlement and
    is unmetered within bounded resource limits. Receipt acceptance does not
    confirm execution completion. MCP is not active.
servers:
  - url: https://api.liftx.io
security: []
paths:
  /integrations/reauth/verify:
    post:
      summary: Verify password or bound Apple token and MFA
      description: >-
        Session-owned Settings contract. Ordinary API keys and TradingView
        capabilities cannot authenticate this route. Use the Liftx Settings
        application; this is not a third-party bot endpoint. Shares
        credential-security admission of 12 requests per minute per source IP
        across these issuance/reauthentication POST operations; separate from
        the five-attempt approval budget. Metadata and revocation are exempt. No
        trading usage quota.
      operationId: post_integrations_reauth_verify
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                operation_id:
                  type: string
                  format: uuid
                proof:
                  $ref: '#/components/schemas/Proof'
              required:
                - operation_id
                - proof
              additionalProperties: false
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Approval'
              examples:
                synthetic:
                  summary: Synthetic purpose-bound approval
                  description: >-
                    Synthetic documentation data, not an account snapshot,
                    executable market configuration or production-availability
                    assertion. IDs, quantities, prices, times and values are
                    illustrative.
                  value:
                    operation_id: 66666666-6666-4666-8666-666666666666
                    approved: true
                    expires_at: 1893456300
        '429':
          description: >-
            Credential security admission limit reached; existing security
            middleware response. Wait before an explicit retry, and never
            automatically replay secret issuance.
        default:
          description: >-
            Integration errors use Error; existing trading handlers retain their
            own JSON or text/plain error codec. Inspect status and content type.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
            text/plain:
              schema:
                type: string
      security:
        - SessionBearer: []
components:
  schemas:
    Proof:
      type: object
      properties:
        password:
          type: string
          maxLength: 128
          writeOnly: true
        apple_token:
          type: string
          maxLength: 4096
          writeOnly: true
        mfa_code:
          type: string
          pattern: ^[0-9]{6}$
          writeOnly: true
      required: []
      additionalProperties: false
      oneOf:
        - required:
            - password
          not:
            required:
              - apple_token
        - required:
            - apple_token
          not:
            required:
              - password
    Approval:
      type: object
      properties:
        operation_id:
          type: string
          format: uuid
        approved:
          const: true
        expires_at:
          type: integer
          format: int64
      required:
        - operation_id
        - approved
        - expires_at
      additionalProperties: false
    Error:
      type: object
      properties:
        success:
          const: false
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
          required:
            - code
            - message
          additionalProperties: false
      required:
        - success
        - error
      additionalProperties: false
  securitySchemes:
    SessionBearer:
      type: http
      scheme: bearer
      bearerFormat: existing authenticated Liftx session

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.