# Validate a two-factor code

`GET https://api.cryptohopper.com/v1/user/validatetwofactor`

Part of [Users](https://www.cryptohopper.com/api-documentation/api-reference/users.md) in the Cryptohopper API reference.

Checks a two-factor authentication code of the user. A wrong code returns HTTP 400 with "Invalid 2FA code."

OAuth scope: `user`

A valid emergency one-time password is used up by this call. Accounts without two-factor authentication accept any non-empty code.

## Headers

| Name | Type | Required | Description |
|---|---|---|---|
| `access-token` | string | yes | The OAuth access token of the user. |

## Query parameters

| Name | Type | Required | Description |
|---|---|---|---|
| `code` | string | yes | Current code from the user's authenticator app, or one of the user's emergency one-time passwords. |

## Example request

```bash
curl "https://api.cryptohopper.com/v1/user/validatetwofactor?code=CODE" \
  -H "access-token: YOUR_ACCESS_TOKEN"
```

## Response

Example response (illustrative values):

```json
{
    "data": "Successfully authenticated."
}
```

Status codes: 200. Errors return JSON with `status`, `error` and `message`, plus a numeric `code` when the error comes from the API itself rather than the gateway.
