One-time Passcodes
Verify a Code
Check the code your user typed against the otpId you got from send. You never fetch the code — you ask Transmit whether it matches.
POST
/v1/otp/verifyParameters
otp_iduuidrequiredThe otpId returned by send.
codestringrequiredThe code as the user entered it, 4 to 8 characters.
Request
curl -X POST https://api.transmitinfra.com/v1/otp/verify \
-H "Authorization: Bearer $TRANSMIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"otp_id": "9c1f0b7a-4d2e-4f61-9a3c-6b0e2d81f5aa",
"code": "418290"
}'{ "data": { "verified": true } }Every possible outcome
A wrong code is not an error — it answers 200 with verified: false. Branch on the field, not on the status code.
// 200 — correct code
{ "data": { "verified": true } }
// 200 — wrong code (attempts 1 to 4)
{ "data": { "verified": false, "reason": "Invalid code" } }
// 200 — correct code submitted again within 60 seconds
{ "data": { "verified": false, "reason": "OTP has already been used" } }
// 429 — fifth wrong code, and every attempt after it
{ "error": { "message": "Too many requests", "code": "RATE_LIMIT_ERROR" } }
// 404 — expired, unknown, or another workspace's otpId
{ "error": { "message": "OTP with id 9c1f0b7a-… not found", "code": "NOT_FOUND" } }Handling the result
- verified: true: The code matched. Mark the user as verified on your side. An
otp.verifiedwebhook also fires. - verified: false: Show the reason and let the user try again.
- 429: The code took five wrong guesses and is locked for the rest of its window. Ask the user to request a new code.
- 404: The code expired after 5 minutes or never existed. Ask the user to request a new code.
A code can be verified once. Afterwards it answers “OTP has already been used” for 60 seconds, then disappears and answers 404.

