A valid access token that Amazon Cognito issued to the user whose software token you want to generate.
The session that should be passed both ways in challenge-response calls to the service. This allows authentication of the user as part of the MFA setup process.