Logto returns 422 with an MFA recommendation when policy is UserControlled. Call POST /profile/mfa/mfa-skipped to skip the binding prompt, then re-submit. Users who already have MFA enrolled still get the TOTP verification flow. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>