MobiariDocs

Finish signing in with a WhatsApp code

POST
/auth/otp/verify

Exchanges the challenge from POST /auth/login and the code from POST /auth/otp/send for a session. The code must have been sent for this challenge. After 5 wrong attempts the code is burned and a new one must be requested.

Header Parameters

Idempotency-Key?string

A unique value (e.g. a UUID) per logical request. Retrying with the same key within 24 hours replays the first response instead of repeating the side effect; the replay carries Idempotent-Replayed: true. Reusing a key for a different request is a 422 idempotency_key_reused; retrying while the first is still running is a 409 idempotency_request_in_progress. JSON bodies up to 1 MB.

Lengthlength <= 255

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/otp/verify" \  -H "Content-Type: application/json" \  -d '{    "challenge": "string",    "code": "123456"  }'
{
  "expires_in": 86400,
  "refresh_token": "string",
  "refresh_token_expires_in": 2592000,
  "session_id": "1ffd059c-17ea-40a8-8aef-70fd0307db82",
  "token": "string",
  "token_type": "Bearer",
  "user": {
    "created_at": "2019-08-24T14:15:22Z",
    "email": "string",
    "full_name": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "is_active": true,
    "locale": null,
    "phone": "string",
    "totp_enabled": true,
    "whatsapp_2fa_enabled": true
  }
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}