curl --request POST \
--url https://mcp.echozero.app/api/auth/verify \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"email": "alice@example.com",
"code": "123456",
"recaptcha": "recaptcha_token_here"
}
'{
"success": true,
"data": {
"status": "success",
"newUser": true,
"onBoardingCompleted": true,
"mfaRequired": true,
"user": {
"id": "507f1f77bcf86cd799439011",
"username": "alice_bob",
"email": "alice@example.com",
"languageCode": "EN",
"emailVerifiedAt": "2023-11-07T05:31:56Z"
},
"tokens": {
"accessToken": "<string>",
"refreshToken": "<string>",
"mfaAccessToken": "<string>"
},
"errorMessage": "<string>",
"unlocksAt": "2023-11-07T05:31:56Z"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Verify the email code and issue tokens
Completes the login / registration flow started by /auth/lookup. On success the response includes tokens.accessToken and tokens.refreshToken. If the account requires MFA, mfaRequired is true and tokens.mfaAccessToken is issued instead — clients must then complete an MFA verification flow.
curl --request POST \
--url https://mcp.echozero.app/api/auth/verify \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"email": "alice@example.com",
"code": "123456",
"recaptcha": "recaptcha_token_here"
}
'{
"success": true,
"data": {
"status": "success",
"newUser": true,
"onBoardingCompleted": true,
"mfaRequired": true,
"user": {
"id": "507f1f77bcf86cd799439011",
"username": "alice_bob",
"email": "alice@example.com",
"languageCode": "EN",
"emailVerifiedAt": "2023-11-07T05:31:56Z"
},
"tokens": {
"accessToken": "<string>",
"refreshToken": "<string>",
"mfaAccessToken": "<string>"
},
"errorMessage": "<string>",
"unlocksAt": "2023-11-07T05:31:56Z"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Headers
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
OpenAPI schema McpVerifyAuthLookupBodyDto. Mirrors GraphQL VerifyAuthLookupInput.
Same email as in /auth/lookup (required for both login and signup verification).
"alice@example.com"
Numeric verification code emailed to the user.
"123456"
reCAPTCHA token. Verification is skipped automatically in non-production environments.
"recaptcha_token_here"