Zernio
Zernio
API Reference

Verify

Send a verification codePOSTGet a verificationGETCheck a verification codePOST
Dashboard
llms.txtOpenAPI
OverviewPlatformsAPI ReferenceResources
Verify

Get a verification

Current state of a verification. status is effective (a pending code past its expiry reads as expired). Verification records are deleted 24 hours after creation, after which this returns 404.


GET
/v1/verify/verifications/{verificationId}

Authorization

bearerAuth
AuthorizationBearer <token>

API key authentication - use your Zernio API key as a Bearer token

In: header

Path Parameters

verificationId*string

Response Body

application/json

application/json

application/json

{  "id": "string",  "status": "pending",  "channel": "sms",  "to": "string",  "expiresAt": "2019-08-24T14:15:22Z",  "attempts": 0,  "maxAttempts": 0,  "sendCount": 0,  "lastSentAt": "2019-08-24T14:15:22Z",  "createdAt": "2019-08-24T14:15:22Z",  "resend": true}
Was this page helpful?

Send a verification code

Generate a one-time code, deliver it to the recipient, and store only its hash. Check the user-typed code with POST /v1/verify/verifications/{verificationId}/check. Re-POSTing for the same (channel, to) while a verification is active RESENDS a fresh code on the existing verification (200 with `resend: true`) instead of creating a new one; resends are limited to one per 60 seconds (429 with `retryAfterSeconds` inside the cooldown). The stored brandName/codeLength/ttlMinutes win on a resend. Codes deliver by SMS from a phone number on your account (`from` optional when you own exactly one SMS-enabled number) and the message uses a fixed template. Each accepted send bills one verification fee plus the standard message rate.

Check a verification code

Verify the code the user typed. Wrong, expired, and exhausted codes answer 200 with `valid: false` and the settled `status` — only an unknown id is a 404. A correct code consumes the verification (single-use, `status: approved`) and fires the `verification.approved` webhook; the 5th wrong attempt settles it as `max_attempts_reached` and fires `verification.failed`.