One-time Passcodes

Verify a Code

Check the code your user typed against the otpId you got from send. You never fetch the code — you ask Transmit whether it matches.
POST/v1/otp/verify

Parameters

otp_iduuidrequired

The otpId returned by send.

codestringrequired

The code as the user entered it, 4 to 8 characters.

Request

curl -X POST https://api.transmitinfra.com/v1/otp/verify \
  -H "Authorization: Bearer $TRANSMIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "otp_id": "9c1f0b7a-4d2e-4f61-9a3c-6b0e2d81f5aa",
    "code": "418290"
  }'
{ "data": { "verified": true } }

Every possible outcome

A wrong code is not an error — it answers 200 with verified: false. Branch on the field, not on the status code.

// 200 — correct code
{ "data": { "verified": true } }

// 200 — wrong code (attempts 1 to 4)
{ "data": { "verified": false, "reason": "Invalid code" } }

// 200 — correct code submitted again within 60 seconds
{ "data": { "verified": false, "reason": "OTP has already been used" } }

// 429 — fifth wrong code, and every attempt after it
{ "error": { "message": "Too many requests", "code": "RATE_LIMIT_ERROR" } }

// 404 — expired, unknown, or another workspace's otpId
{ "error": { "message": "OTP with id 9c1f0b7a-… not found", "code": "NOT_FOUND" } }

Handling the result

  • verified: true: The code matched. Mark the user as verified on your side. An otp.verified webhook also fires.
  • verified: false: Show the reason and let the user try again.
  • 429: The code took five wrong guesses and is locked for the rest of its window. Ask the user to request a new code.
  • 404: The code expired after 5 minutes or never existed. Ask the user to request a new code.
A code can be verified once. Afterwards it answers “OTP has already been used” for 60 seconds, then disappears and answers 404.