Verify the login OTP and issue access + refresh tokens

Exchanges the OTP challenge for an access token (12h) and a refresh token
(30 days). The challenge is single-use and deleted on success.

Send the access token as Authorization: Bearer <accessToken> for all
developer-portal endpoints. Rotate it via refresh before expiry.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
required

Challenge identifier issued by login (and echoed back by login/resend-otp)

string
required

Six-digit OTP delivered via email and SMS

Responses

400

Challenge expired or not found.

401

Invalid OTP, or the challenge exceeded 5 attempts.

Language
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json