curl --request POST \
--url https://api.robase.dev/v1/otp/verify \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"otp_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"code": "123456"
}
'import requests
url = "https://api.robase.dev/v1/otp/verify"
payload = {
"otp_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"code": "123456"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({otp_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a', code: '123456'})
};
fetch('https://api.robase.dev/v1/otp/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.robase.dev/v1/otp/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'otp_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'code' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.robase.dev/v1/otp/verify"
payload := strings.NewReader("{\n \"otp_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"code\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.robase.dev/v1/otp/verify")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"otp_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"code\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.robase.dev/v1/otp/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"otp_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"code\": \"123456\"\n}"
response = http.request(request)
puts response.read_bodyVerify an OTP
POST /v1/otp/verify — constant-time check. Wrong codes with attempts left are 200 valid:false.
curl --request POST \
--url https://api.robase.dev/v1/otp/verify \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"otp_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"code": "123456"
}
'import requests
url = "https://api.robase.dev/v1/otp/verify"
payload = {
"otp_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"code": "123456"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({otp_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a', code: '123456'})
};
fetch('https://api.robase.dev/v1/otp/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.robase.dev/v1/otp/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'otp_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'code' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.robase.dev/v1/otp/verify"
payload := strings.NewReader("{\n \"otp_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"code\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.robase.dev/v1/otp/verify")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"otp_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"code\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.robase.dev/v1/otp/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"otp_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"code\": \"123456\"\n}"
response = http.request(request)
puts response.read_bodyAuthorizations
Your Robase API key. Starts with robe_. Include as Authorization: Bearer robe_...
Headers
Opaque client-generated key. Replaying the same key within 24 hours returns the original response instead of performing the action again. Recommended for every send so a network-level retry cannot double-charge.
255Body
Response
The code was checked. valid reports whether it matched; a false
result still counts against the attempt budget.
Whether the submitted code matched
The OTP's state after this attempt. verified on success;
failed once the attempt budget is exhausted.
pending, sent, verified, failed Verification attempts made so far, including this one
Attempts left before the OTP is burned. Present only when valid is false.