Skip to main content
POST
Verify OTP and return tokens
Validates the submitted OTP code, creates/updates the user in Auth0 and MongoDB, and returns Auth0 tokens so the client can treat OTP users like any other session.

Headers

Request Body

Response

Error Codes

Notes

  • The accessToken is an Auth0 JWT that can be used with all authenticated endpoints
  • The refreshToken can be used with /api/v1/auth/refresh to get new tokens
  • The synthetic email (phone@sms.handauncle.app) is used internally for Auth0 database connection

Headers

x-device-id
string
required

Unique identifier for the calling device or installation.

Minimum string length: 1
x-platform
enum<string>

Client platform (ios, android, web).

Available options:
ios,
android,
web

Body

application/json
phone
string
required

Phone number. Accepts 10-digit numbers (9876543210), numbers with country code (919876543210), or E.164 format (+919876543210). The +91 prefix is automatically added for 10-digit numbers.

Example:

"9876543210"

otp
string
required

6-digit verification code.

Pattern: ^\d{6}$
Example:

"123456"

Response

Tokens issued

success
enum<boolean>
required
Available options:
true
data
object
required
meta
object
required