← All action domains

Security

2 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.

Account security

security.getreadadmin only

Read this account's security posture: whether two-factor authentication is required for every member. Changes nothing.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/security.get \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool security_get at https://app.chirply.io/api/mcp, same bearer token, same input.

Require two-factor for everyone

security.set_require_mfawriteconfirmadmin only

Turn the account-wide two-factor requirement on or off. Turning it ON locks every teammate without a verified authenticator app out of the account until they enroll — on their next navigation they are taken to a mandatory set-up screen and can do nothing else there but enroll or sign out. It is refused unless the acting person (for an API key, the account owner) already has a verified authenticator, so the requirement can never lock out the person who could undo it. Turning it OFF simply stops requiring enrollment; existing authenticators are untouched.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
require_mfabooleanrequiredTrue to require every member of this account to set up two-factor authentication before they can work; false to make it optional again.

Example

curl -X POST https://app.chirply.io/api/v1/actions/security.set_require_mfa \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "require_mfa": true
  }'
Test with your API key

Over MCP the same operation is the tool security_set_require_mfa at https://app.chirply.io/api/mcp, same bearer token, same input.

The machine-readable version of this page is GET https://app.chirply.io/api/v1/actions?domain=security — same operations, with full JSON Schemas. Authentication, errors and rate limits are covered in the API documentation home.