If enabled: never returns secret nor otpauth_uri. If disabled: returns pending secret + otpauth_uri for enrollment (cache, not DB).
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
OK
"OK"
"OK"
false
"user@example.com"
"BASE32SECRET..."
"otpauth://totp/Flowxi:user@example.com?secret=BASE32SECRET&issuer=Flowxi"
"Flowxi"
600