Skip to navigation

One-time passcodes

Verify users with OTPs sent over SMS

The OTP endpoints generate, deliver and verify one-time passcodes, so you don’t have to store codes yourself.

1

Request a passcode

Call Request OTP with the recipient and how long the code should remain valid.

curl -X POST http://gateway-api.e97e9e55a5d242f9a139.uksouth.aksapp.io/v2/otps \
-H "X-API-Key: $ESENDEX_API_KEY" \
-H "AccountReference: EX0000000" \
-H "Content-Type: application/json" \
-d '{
"recipient": "447700900000",
"channel": "SMS",
"from": "Esendex",
"validitySeconds": 300
}'

The response includes the messageId of the passcode message and when the code expiresAt.

2

Verify the passcode

When the user enters the code, send it to Verify OTP along with the same recipient.

curl -X POST http://gateway-api.e97e9e55a5d242f9a139.uksouth.aksapp.io/v2/otps/verify \
-H "X-API-Key: $ESENDEX_API_KEY" \
-H "AccountReference: EX0000000" \
-H "Content-Type: application/json" \
-d '{ "recipient": "447700900000", "otp": "123456" }'

Keep validitySeconds short (a few minutes) and rate-limit OTP requests per recipient to reduce fraud and cost.