Verify OTP and return tokens
curl --request POST \
--url https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp \
--header 'Content-Type: application/json' \
--header 'x-device-id: <x-device-id>' \
--data '
{
"phone": "9876543210",
"otp": "123456"
}
'import requests
url = "https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp"
payload = {
"phone": "9876543210",
"otp": "123456"
}
headers = {
"x-device-id": "<x-device-id>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-device-id': '<x-device-id>', 'Content-Type': 'application/json'},
body: JSON.stringify({phone: '9876543210', otp: '123456'})
};
fetch('https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'phone' => '9876543210',
'otp' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-device-id: <x-device-id>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp"
payload := strings.NewReader("{\n \"phone\": \"9876543210\",\n \"otp\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-device-id", "<x-device-id>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp")
.header("x-device-id", "<x-device-id>")
.header("Content-Type", "application/json")
.body("{\n \"phone\": \"9876543210\",\n \"otp\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-device-id"] = '<x-device-id>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"phone\": \"9876543210\",\n \"otp\": \"123456\"\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"accessToken": "<string>",
"idToken": "<string>",
"refreshToken": "<string>",
"expiresIn": 123,
"user": {
"id": "<string>",
"email": "jsmith@example.com",
"name": "<string>",
"picture": "<string>",
"emailVerified": true,
"phone": "<string>"
}
},
"meta": {
"timestamp": "2023-11-07T05:31:56Z",
"requestId": "<string>"
}
}{
"success": false,
"error": {
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)",
"code": "VALIDATION_ERROR",
"details": [
{
"field": "phone",
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)"
}
]
},
"meta": {
"timestamp": "2023-11-07T05:31:56Z",
"requestId": "<string>"
}
}{
"success": false,
"error": {
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)",
"code": "VALIDATION_ERROR",
"details": [
{
"field": "phone",
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)"
}
]
},
"meta": {
"timestamp": "2023-11-07T05:31:56Z",
"requestId": "<string>"
}
}Auth service
Verify OTP
POST
/
api
/
v1
/
auth
/
verify-otp
Verify OTP and return tokens
curl --request POST \
--url https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp \
--header 'Content-Type: application/json' \
--header 'x-device-id: <x-device-id>' \
--data '
{
"phone": "9876543210",
"otp": "123456"
}
'import requests
url = "https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp"
payload = {
"phone": "9876543210",
"otp": "123456"
}
headers = {
"x-device-id": "<x-device-id>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-device-id': '<x-device-id>', 'Content-Type': 'application/json'},
body: JSON.stringify({phone: '9876543210', otp: '123456'})
};
fetch('https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'phone' => '9876543210',
'otp' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-device-id: <x-device-id>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp"
payload := strings.NewReader("{\n \"phone\": \"9876543210\",\n \"otp\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-device-id", "<x-device-id>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp")
.header("x-device-id", "<x-device-id>")
.header("Content-Type", "application/json")
.body("{\n \"phone\": \"9876543210\",\n \"otp\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://handauncle-backend-prod-205012263523.asia-south1.run.app/api/v1/auth/verify-otp")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-device-id"] = '<x-device-id>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"phone\": \"9876543210\",\n \"otp\": \"123456\"\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"accessToken": "<string>",
"idToken": "<string>",
"refreshToken": "<string>",
"expiresIn": 123,
"user": {
"id": "<string>",
"email": "jsmith@example.com",
"name": "<string>",
"picture": "<string>",
"emailVerified": true,
"phone": "<string>"
}
},
"meta": {
"timestamp": "2023-11-07T05:31:56Z",
"requestId": "<string>"
}
}{
"success": false,
"error": {
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)",
"code": "VALIDATION_ERROR",
"details": [
{
"field": "phone",
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)"
}
]
},
"meta": {
"timestamp": "2023-11-07T05:31:56Z",
"requestId": "<string>"
}
}{
"success": false,
"error": {
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)",
"code": "VALIDATION_ERROR",
"details": [
{
"field": "phone",
"message": "Please enter a valid 10-digit phone number (e.g., 9876543210)"
}
]
},
"meta": {
"timestamp": "2023-11-07T05:31:56Z",
"requestId": "<string>"
}
}Validates the submitted OTP code, creates/updates the user in Auth0 and MongoDB,
and returns Auth0 tokens so the client can treat OTP users like any other session.
Headers
| Header | Required | Description |
|---|---|---|
x-device-id | Yes | Unique device identifier |
x-platform | No | Platform type: ios, android, or web |
Request Body
{
"phone": "+919876543210",
"otp": "123456"
}
Response
{
"success": true,
"data": {
"accessToken": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"idToken": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"refreshToken": "v1.MjAyNS0xMi0wMlQwODowMDowMC4wMDBa...",
"expiresIn": 86400,
"user": {
"id": "auth0|692e9f465b1b4e6753627a4f",
"phone": "+919876543210",
"name": "HU Phone 3210",
"phoneVerified": true,
"email": "919876543210@sms.handauncle.app"
}
},
"meta": {
"timestamp": "2025-12-02T08:00:00.000Z",
"request_id": "uuid"
}
}
Error Codes
| Status | Description |
|---|---|
400 | Invalid or expired OTP |
401 | Maximum verification attempts exceeded |
502 | Auth0 or Exotel service failure |
Notes
- The
accessTokenis an Auth0 JWT that can be used with all authenticated endpoints - The
refreshTokencan be used with/api/v1/auth/refreshto get new tokens - The synthetic email (
phone@sms.handauncle.app) is used internally for Auth0 database connection
Headers
Unique identifier for the calling device or installation.
Minimum string length:
1Client platform (ios, android, web).
Available options:
ios, android, web Body
application/json
Phone number. Accepts 10-digit numbers (9876543210), numbers with country code (919876543210), or E.164 format (+919876543210). The +91 prefix is automatically added for 10-digit numbers.
Example:
"9876543210"
6-digit verification code.
Pattern:
^\d{6}$Example:
"123456"
⌘I