Get a verification
Current state of a verification. status is effective (a pending code
past its expiry reads as expired). Verification records are deleted
24 hours after creation, after which this returns 404.
Authorization
bearerAuth API key authentication - use your Zernio API key as a Bearer token
In: header
Path Parameters
Response Body
application/json
application/json
application/json
{ "id": "string", "status": "pending", "channel": "sms", "to": "string", "expiresAt": "2019-08-24T14:15:22Z", "attempts": 0, "maxAttempts": 0, "sendCount": 0, "lastSentAt": "2019-08-24T14:15:22Z", "createdAt": "2019-08-24T14:15:22Z", "resend": true}Send a verification code
Generate a one-time code, deliver it to the recipient, and store only its hash. Check the user-typed code with POST /v1/verify/verifications/{verificationId}/check. Re-POSTing for the same (channel, to) while a verification is active RESENDS a fresh code on the existing verification (200 with `resend: true`) instead of creating a new one; resends are limited to one per 60 seconds (429 with `retryAfterSeconds` inside the cooldown). The stored brandName/codeLength/ttlMinutes win on a resend. Codes deliver by SMS from a phone number on your account (`from` optional when you own exactly one SMS-enabled number) and the message uses a fixed template. Each accepted send bills one verification fee plus the standard message rate.
Check a verification code
Verify the code the user typed. Wrong, expired, and exhausted codes answer 200 with `valid: false` and the settled `status` — only an unknown id is a 404. A correct code consumes the verification (single-use, `status: approved`) and fires the `verification.approved` webhook; the 5th wrong attempt settles it as `max_attempts_reached` and fires `verification.failed`.