curl --request POST \
--url https://mcp.echozero.app/api/auth/lookup \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"email": "alice@example.com",
"recaptcha": "recaptcha_token_here",
"fingerprint": "fp_browser_abc123"
}
'{
"success": true,
"data": {
"status": "success",
"userId": "<string>",
"email": "<string>",
"nextRequestAt": 123,
"mfaRequired": true,
"errorMessage": "<string>",
"unlocksAt": "2023-11-07T05:31:56Z"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Request an email verification code (login or signup)
Unified login + registration lookup. If the email is already registered, an email login code is sent. Otherwise the optional signup fields are consumed and a registration code is sent.
curl --request POST \
--url https://mcp.echozero.app/api/auth/lookup \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"email": "alice@example.com",
"recaptcha": "recaptcha_token_here",
"fingerprint": "fp_browser_abc123"
}
'{
"success": true,
"data": {
"status": "success",
"userId": "<string>",
"email": "<string>",
"nextRequestAt": 123,
"mfaRequired": true,
"errorMessage": "<string>",
"unlocksAt": "2023-11-07T05:31:56Z"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Headers
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
OpenAPI schema McpRequestAuthLookupBodyDto. Mirrors GraphQL RequestAuthLookupInput.
The user's email address to which the lookup code will be sent.
"alice@example.com"
reCAPTCHA token. Verification is skipped automatically in non-production environments.
"recaptcha_token_here"
Device fingerprint / visitor id generated by the client for session binding.
"fp_browser_abc123"
Desired username (only used when registering a new user).
5"alice_bob"
Opt-in to marketing offers / communications (new users only).
Indicates the user has accepted the platform's terms and conditions (new users only).
Promotional code (new users only).
"WELCOME2025"
Referral code from an invitation link (new users only).
"REF-ABC-123"
Username of the referring user (new users only).
"referrer_user"
User id of the referring user (new users only).
"507f1f77bcf86cd799439011"