Updated on 2026-07-22 GMT+08:00

Creating a Virtual MFA Device

Function

This API is used to create a virtual MFA device.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

iam:mfa:createVirtualMFADeviceV5

Write

mfa *

-

-

-

URI

POST /v5/virtual-mfa-devices

Request Parameters

Table 1 Request body parameters

Parameter

Mandatory

Type

Description

virtual_mfa_device_name

Yes

String

Definition:

MFA device name.

Constraints:

The value contains 1 to 64 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

Range:

N/A

Default Value:

N/A

user_id

Yes

String

Definition:

IAM user ID, which is globally unique.

Constraints:

Character string type. It is a standard IAM user ID generated by the platform.

Range:

N/A

Default Value:

N/A

Response Parameters

Status code: 201

Table 2 Response body parameters

Parameter

Type

Description

virtual_mfa_device

virtual_mfa_device object

Definition:

MFA device.

Range:

N/A

Table 3 virtual_mfa_device

Parameter

Type

Description

serial_number

String

Definition:

Serial number of the MFA device, which is automatically generated when the MFA device is created.

Range:

N/A

base32_string_seed

String

Definition:

Key information, which a third-party system can use to generate an image verification code.

Range:

N/A

Status code: 400

Table 4 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 403

Table 5 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

encoded_authorization_message

String

Definition :

Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link.

Range:

N/A.

Status code: 404

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 409

Table 7 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Example Requests

Creating a virtual MFA device name for IAM user xxx

POST https://{endpoint}/v5/virtual-mfa-devices

{
  "virtual_mfa_device_name" : "name",
  "user_id" : "xxx"
}

Example Responses

Status code: 201

Successful

{
  "virtual_mfa_device" : {
    "serial_number" : "iam::accountid:mfa:name",
    "base32_string_seed" : "seed"
  }
}

Status Codes

Status Code

Description

201

Successful

400

Bad request

403

Forbidden

404

Not found

409

Conflict

Error Codes

See Error Codes.