
diegom.56770 (Customer) asked a question.
Hi to all, i have next question:
I have a spa application configured in okta and works ok but when i make a policy for mfa (mail) i have next error: "login_required, error.description: The client specified not to prompt, but the client app requires re-authentication or MFA." do need i any special for my okta widget? okta manages mfa process?

HiDiego ,
If you are using the self hosted Okta sign-in widget this is expected behavior as it does not support the application level MFA. The solution would be to either redirect the users to the Okta /authorize endpoint or use organization level MFA under Admin >> Security >> Authentication >> Sign On
If you are not using either app lvl mfa nor application level policy please go ahead and open a case with us to further investigate.