admin_second_factor_refused
This code is raised on a non-customer surface (the /internal voice-runtime audience or telephony provider callbacks). It is excluded from the customer OpenAPI document and is registered here so an operator reading a log line has one place to look.
A second-factor verification did not succeed. Unknown challenge, wrong code, expired, guess budget spent (five per challenge), one minted by a different session, and an enrolled authenticator answered with the wrong kind of code are one indistinguishable refusal on purpose - the same posture as admin_step_up_required, and the operator's remedy is the same in every case: request another code. The reason is in the security log.
Problem shape
Every non-2xx response is an RFC 9457 application/problem+json body. The type URI below is stable and machine-matchable, so branch on the final path segment (the code) and treat the status as redundant confirmation. See the error-handling guide.
{
"type": "https://docs.vocapable.com/errors/admin_second_factor_refused",
"title": "…",
"status": 403,
"detail": "…",
"instance": "/v1/…"
}