Verify OTP code
curl --request POST \
--url https://{defaultHost}/v1/auth/{app_id}/otps/verify \
--header 'Authorization: Bearer <token>' \
--header 'X-Authorization: <api-key>'import requests
url = "https://{defaultHost}/v1/auth/{app_id}/otps/verify"
headers = {
"Authorization": "Bearer <token>",
"X-Authorization": "<api-key>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'X-Authorization': '<api-key>'}
};
fetch('https://{defaultHost}/v1/auth/{app_id}/otps/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{defaultHost}/v1/auth/{app_id}/otps/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://{defaultHost}/v1/auth/{app_id}/otps/verify"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{defaultHost}/v1/auth/{app_id}/otps/verify")
.header("Authorization", "Bearer <token>")
.header("X-Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{defaultHost}/v1/auth/{app_id}/otps/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"access": "<string>",
"refresh": "<string>",
"csrf": "<string>",
"access_expires_at": "2023-11-07T05:31:56Z",
"refresh_expires_at": "2023-11-07T05:31:56Z",
"user_id": "<string>",
"key_id": "<string>"
}{
"error": "OTP parameter required",
"error_code": "otp_required"
}{
"error": "Login blocked for security reasons",
"error_code": "security_block"
}{
"error": "Challenge not found",
"error_code": "challenge_not_found"
}OTP
Verify OTP code
Verify a one-time passcode and return session tokens. The user_id parameter is the challenge token returned from the /otps/login endpoint.
POST
/
v1
/
auth
/
{app_id}
/
otps
/
verify
Verify OTP code
curl --request POST \
--url https://{defaultHost}/v1/auth/{app_id}/otps/verify \
--header 'Authorization: Bearer <token>' \
--header 'X-Authorization: <api-key>'import requests
url = "https://{defaultHost}/v1/auth/{app_id}/otps/verify"
headers = {
"Authorization": "Bearer <token>",
"X-Authorization": "<api-key>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'X-Authorization': '<api-key>'}
};
fetch('https://{defaultHost}/v1/auth/{app_id}/otps/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{defaultHost}/v1/auth/{app_id}/otps/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://{defaultHost}/v1/auth/{app_id}/otps/verify"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{defaultHost}/v1/auth/{app_id}/otps/verify")
.header("Authorization", "Bearer <token>")
.header("X-Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{defaultHost}/v1/auth/{app_id}/otps/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"access": "<string>",
"refresh": "<string>",
"csrf": "<string>",
"access_expires_at": "2023-11-07T05:31:56Z",
"refresh_expires_at": "2023-11-07T05:31:56Z",
"user_id": "<string>",
"key_id": "<string>"
}{
"error": "OTP parameter required",
"error_code": "otp_required"
}{
"error": "Login blocked for security reasons",
"error_code": "security_block"
}{
"error": "Challenge not found",
"error_code": "challenge_not_found"
}Authorizations
API Secret token
User Access token
Path Parameters
App ID
Response
OTP verified successfully
JWT access token
JWT refresh token
CSRF token for protected operations
Access token expiration timestamp
Refresh token expiration timestamp
App user ID
App key ID for JWT verification
Was this page helpful?
⌘I