post
https://api.valmarpayments.com/auth/login/challenge
Complete a login challenge returned by POST /auth/login. Send the session and challengeName from the previous response plus responses matching the challenge (for example EMAIL_OTP_CODE, SOFTWARE_TOKEN_MFA_CODE, NEW_PASSWORD, or device-SRP fields). A challenge is an expected step in the login flow, not an edge case to avoid.