PingOne Platform APIs

Step 7: Create an SMS MFA sign-on policy action

 

POST {{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions

The POST {{apiPath}}/environments/{{envID}}/signOnPolicies/{{policyID}}/actions operation creates the MULTI_FACTOR_AUTHENTICATION sign-on policy action resource, which is associated with the sign-on policy ({{policyID}}) specified in the request URL. This action will send a one-time passcode to the user’s SMS device.

For a sign-on action that supports a multi-factor authentication action, the sign-on policy action must enable at least one MFA device type. This action enables the sms device types and sets the email device type to false.

In this use case, the priority property in the request body is set to 1 (the highest priority) to ensure that this MULTI_FACTOR_AUTHENTICATION action is the first sign-on action.

Headers

Authorization      Bearer {{accessToken}}

Content-Type      application/json

Body

raw ( application/json )

{
    "priority": 5,
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "sms": {
        "enabled": true
    },
    "email": {
        "enabled": false
    }
}

Example Request

  • cURL

  • C#

  • Go

  • HTTP

  • Java

  • jQuery

  • NodeJS

  • Python

  • PHP

  • Ruby

  • Swift

curl --location --globoff '{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer {{accessToken}}' \
--data '{
    "priority": 5,
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "sms": {
        "enabled": true
    },
    "email": {
        "enabled": false
    }
}'
var options = new RestClientOptions("{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions")
{
  MaxTimeout = -1,
};
var client = new RestClient(options);
var request = new RestRequest("", Method.Post);
request.AddHeader("Content-Type", "application/json");
request.AddHeader("Authorization", "Bearer {{accessToken}}");
var body = @"{" + "\n" +
@"    ""priority"": 5," + "\n" +
@"    ""type"": ""MULTI_FACTOR_AUTHENTICATION""," + "\n" +
@"    ""sms"": {" + "\n" +
@"        ""enabled"": true" + "\n" +
@"    }," + "\n" +
@"    ""email"": {" + "\n" +
@"        ""enabled"": false" + "\n" +
@"    }" + "\n" +
@"}";
request.AddStringBody(body, DataFormat.Json);
RestResponse response = await client.ExecuteAsync(request);
Console.WriteLine(response.Content);
package main

import (
  "fmt"
  "strings"
  "net/http"
  "io"
)

func main() {

  url := "{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions"
  method := "POST"

  payload := strings.NewReader(`{
    "priority": 5,
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "sms": {
        "enabled": true
    },
    "email": {
        "enabled": false
    }
}`)

  client := &http.Client {
  }
  req, err := http.NewRequest(method, url, payload)

  if err != nil {
    fmt.Println(err)
    return
  }
  req.Header.Add("Content-Type", "application/json")
  req.Header.Add("Authorization", "Bearer {{accessToken}}")

  res, err := client.Do(req)
  if err != nil {
    fmt.Println(err)
    return
  }
  defer res.Body.Close()

  body, err := io.ReadAll(res.Body)
  if err != nil {
    fmt.Println(err)
    return
  }
  fmt.Println(string(body))
}
POST /environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions HTTP/1.1
Host: {{apiPath}}
Content-Type: application/json
Authorization: Bearer {{accessToken}}

{
    "priority": 5,
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "sms": {
        "enabled": true
    },
    "email": {
        "enabled": false
    }
}
OkHttpClient client = new OkHttpClient().newBuilder()
  .build();
MediaType mediaType = MediaType.parse("application/json");
RequestBody body = RequestBody.create(mediaType, "{\n    \"priority\": 5,\n    \"type\": \"MULTI_FACTOR_AUTHENTICATION\",\n    \"sms\": {\n        \"enabled\": true\n    },\n    \"email\": {\n        \"enabled\": false\n    }\n}");
Request request = new Request.Builder()
  .url("{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions")
  .method("POST", body)
  .addHeader("Content-Type", "application/json")
  .addHeader("Authorization", "Bearer {{accessToken}}")
  .build();
Response response = client.newCall(request).execute();
var settings = {
  "url": "{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions",
  "method": "POST",
  "timeout": 0,
  "headers": {
    "Content-Type": "application/json",
    "Authorization": "Bearer {{accessToken}}"
  },
  "data": JSON.stringify({
    "priority": 5,
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "sms": {
      "enabled": true
    },
    "email": {
      "enabled": false
    }
  }),
};

$.ajax(settings).done(function (response) {
  console.log(response);
});
var request = require('request');
var options = {
  'method': 'POST',
  'url': '{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions',
  'headers': {
    'Content-Type': 'application/json',
    'Authorization': 'Bearer {{accessToken}}'
  },
  body: JSON.stringify({
    "priority": 5,
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "sms": {
      "enabled": true
    },
    "email": {
      "enabled": false
    }
  })

};
request(options, function (error, response) {
  if (error) throw new Error(error);
  console.log(response.body);
});
import requests
import json

url = "{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions"

payload = json.dumps({
  "priority": 5,
  "type": "MULTI_FACTOR_AUTHENTICATION",
  "sms": {
    "enabled": True
  },
  "email": {
    "enabled": False
  }
})
headers = {
  'Content-Type': 'application/json',
  'Authorization': 'Bearer {{accessToken}}'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)
<?php
require_once 'HTTP/Request2.php';
$request = new HTTP_Request2();
$request->setUrl('{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions');
$request->setMethod(HTTP_Request2::METHOD_POST);
$request->setConfig(array(
  'follow_redirects' => TRUE
));
$request->setHeader(array(
  'Content-Type' => 'application/json',
  'Authorization' => 'Bearer {{accessToken}}'
));
$request->setBody('{\n    "priority": 5,\n    "type": "MULTI_FACTOR_AUTHENTICATION",\n    "sms": {\n        "enabled": true\n    },\n    "email": {\n        "enabled": false\n    }\n}');
try {
  $response = $request->send();
  if ($response->getStatus() == 200) {
    echo $response->getBody();
  }
  else {
    echo 'Unexpected HTTP status: ' . $response->getStatus() . ' ' .
    $response->getReasonPhrase();
  }
}
catch(HTTP_Request2_Exception $e) {
  echo 'Error: ' . $e->getMessage();
}
require "uri"
require "json"
require "net/http"

url = URI("{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions")

http = Net::HTTP.new(url.host, url.port);
request = Net::HTTP::Post.new(url)
request["Content-Type"] = "application/json"
request["Authorization"] = "Bearer {{accessToken}}"
request.body = JSON.dump({
  "priority": 5,
  "type": "MULTI_FACTOR_AUTHENTICATION",
  "sms": {
    "enabled": true
  },
  "email": {
    "enabled": false
  }
})

response = http.request(request)
puts response.read_body
let parameters = "{\n    \"priority\": 5,\n    \"type\": \"MULTI_FACTOR_AUTHENTICATION\",\n    \"sms\": {\n        \"enabled\": true\n    },\n    \"email\": {\n        \"enabled\": false\n    }\n}"
let postData = parameters.data(using: .utf8)

var request = URLRequest(url: URL(string: "{{apiPath}}/environments/{{envID}}/signOnPolicies/{{mfaSignonPolicyID}}/actions")!,timeoutInterval: Double.infinity)
request.addValue("application/json", forHTTPHeaderField: "Content-Type")
request.addValue("Bearer {{accessToken}}", forHTTPHeaderField: "Authorization")

request.httpMethod = "POST"
request.httpBody = postData

let task = URLSession.shared.dataTask(with: request) { data, response, error in
  guard let data = data else {
    print(String(describing: error))
    return
  }
  print(String(data: data, encoding: .utf8)!)
}

task.resume()

Example Response

201 Created

{
    "_links": {
        "self": {
            "href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/signOnPolicies/c4a8f4ad-c088-45c5-8b36-49edf8d3f4a0/actions/1c7d39f5-5d50-45e5-b3f0-6fe96c9cccec"
        },
        "environment": {
            "href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6"
        },
        "signOnPolicy": {
            "href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/signOnPolicies/c4a8f4ad-c088-45c5-8b36-49edf8d3f4a0"
        }
    },
    "id": "1c7d39f5-5d50-45e5-b3f0-6fe96c9cccec",
    "environment": {
        "id": "abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6"
    },
    "type": "MULTI_FACTOR_AUTHENTICATION",
    "signOnPolicy": {
        "id": "c4a8f4ad-c088-45c5-8b36-49edf8d3f4a0"
    },
    "priority": 5,
    "sms": {
        "enabled": true
    },
    "email": {
        "enabled": false
    }
}