PATCH /api/users/{userId}/logto-configs

Update the exposed portion of a user's logto config. Supports updating MFA states (enabled, skipped, skipMfaOnSignIn) and passkey sign-in states (skipped). All fields are optional — only provided fields will be updated.

Path parameters

  • userId string Required

    The unique identifier of the user.

application/json

Body Required

  • mfa object
    Hide mfa attributes Show mfa attributes object
    • enabled boolean

      Set whether MFA is enabled for the user.

    • skipped boolean

      Set whether the user is marked as having skipped MFA binding.

    • skipMfaOnSignIn boolean

      Set whether the user has opted to skip MFA verification on sign-in. This is ignored when the MFA policy is mandatory.

  • passkeySignIn object
    Hide passkeySignIn attribute Show passkeySignIn attribute object
    • skipped boolean

      Set whether the user has persistently skipped binding a passkey for sign-in.

Responses

  • 200 application/json

    The exposed logto config fields were updated successfully.

    Hide response attributes Show response attributes object
    • mfa object Required
      Hide mfa attributes Show mfa attributes object
      • enabled boolean
      • skipped boolean Required
      • skipMfaOnSignIn boolean Required
    • passkeySignIn object Required
      Hide passkeySignIn attribute Show passkeySignIn attribute object
      • skipped boolean Required
  • 400

    Bad Request

  • 401

    Unauthorized

  • 403

    Forbidden

  • 404

    Not Found

PATCH /api/users/{userId}/logto-configs
curl \
 --request PATCH 'https://[tenant_id].logto.app/api/users/{userId}/logto-configs' \
 --header "Authorization: Bearer $ACCESS_TOKEN" \
 --header "Content-Type: application/json" \
 --data '{"mfa":{"enabled":true,"skipped":true,"skipMfaOnSignIn":true},"passkeySignIn":{"skipped":true}}'
Request examples
{
  "mfa": {
    "enabled": true,
    "skipped": true,
    "skipMfaOnSignIn": true
  },
  "passkeySignIn": {
    "skipped": true
  }
}
Response examples (200)
{
  "mfa": {
    "enabled": true,
    "skipped": true,
    "skipMfaOnSignIn": true
  },
  "passkeySignIn": {
    "skipped": true
  }
}