Skip to main content
POST

Headers

x-signature
string
required

Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.

x-timestamp
string
required

Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.

Body

application/json

OpenAPI schema McpVerifyAuthLookupBodyDto. Mirrors GraphQL VerifyAuthLookupInput.

email
string
required

Same email as in /auth/lookup (required for both login and signup verification).

Example:

"alice@example.com"

code
string
required

Numeric verification code emailed to the user.

Example:

"123456"

recaptcha
string
required

reCAPTCHA token. Verification is skipped automatically in non-production environments.

Example:

"recaptcha_token_here"

Response

Verification succeeded. Tokens issued unless MFA is required.

success
boolean
required
Example:

true

data
object
required

Endpoint-specific payload