verifyTotp

suspend fun verifyTotp(code: String, userJwt: String): AuthResult.Authenticated

Submits a TOTP code for a login that returned AuthResult.TotpRequired.

Pass userJwt back exactly as received. A wrong code does not consume it, so re-prompting is the normal path; if it expires, or the process is killed before this call, the login restarts from the beginning — there is no refresh path.

On success the session is persisted before it is returned, on the same terms as handleRedirect, and the grant that opened the TOTP step stops replaying as a step: a redirect re-delivered afterwards resolves to this same AuthResult.Authenticated rather than prompting for a code the user has already entered.

Throws

when userJwt cannot be read. Raised before the network call, so a bad JWT never costs the user a live code.

when the validation response carries no session token.