Create a new CodeVerification record and sends the code to the specified identifier. The code verification can be used to verify the given identifier. Once the interaction already carries a subject (the subject pinned by a step-up authentication, or an identified user), the identifier may carry only its type: the code is then sent to that user's primary email or phone with the SignIn template, the subject is read from the interaction storage, and the request never carries a raw identifier. This variant is only accepted with the SignIn interaction event.
Responses
-
The verification code has been successfully sent.
-
An invalid identifier was provided.
-
Forbidden
-
The identifier carried only its type but the interaction carries no subject, or the subject has no primary identifier of that type (
session.identifier_not_found). -
Unprocessable Content
-
Too Many Requests
-
The connector for sending the verification code is not configured.
curl \
--request POST 'https://[tenant_id].logto.app/api/experience/verification/verification-code' \
--header "Content-Type: application/json" \
--data '{
"identifier": {
"type": "string",
"value": "string"
},
"interactionEvent": "SignIn"
}'
{
"identifier": {
"type": "string",
"value": "string"
},
"interactionEvent": "SignIn"
}
{
"identifier": {
"type": "email"
}
}
{
"verificationId": "string"
}