admin_totp_already_enrolled
This code is raised on a non-customer surface (the /internal voice-runtime audience or telephony provider callbacks). It is excluded from the customer OpenAPI document and is registered here so an operator reading a log line has one place to look.
Authenticator enrolment was started, or a set of recovery codes requested, for an account that already has a confirmed authenticator. Replacing a working authenticator without proving the current one is exactly what a stolen console session would do, so moving to a new device is disenrol-then-enrol.
Problem shape
Every non-2xx response is an RFC 9457 application/problem+json body. The type URI below is stable and machine-matchable, so branch on the final path segment (the code) and treat the status as redundant confirmation. See the error-handling guide.
{
"type": "https://docs.vocapable.com/errors/admin_totp_already_enrolled",
"title": "…",
"status": 409,
"detail": "…",
"instance": "/v1/…"
}