Codes model
Codes support one-time verification workflows such as user verification and one-time passwords. A code is sensitive, short-lived workflow data; never place a real code or recipient in documentation or logs.
Public operations
The current public API Reference contains these code operations:
| Action | Method | Resource | Purpose |
|---|---|---|---|
| Generate a code | POST | /codes/generate | Validate delivery data, create or reuse a code under rate limits, and dispatch delivery. |
| Verify a code | GET | /codes/verify | Verify a code using query parameters. |
| Verify a code | POST | /codes/verify | Verify a code using a JSON request body. |
The current public API reference does not document GET /codes/generate; its public availability is unconfirmed.
The operation guide specifies request fields, required values, security, responses, and errors.
Model fields
The model described here contains these workflow fields:
| Field | Purpose |
|---|---|
id | Numeric record identifier. |
sender_id | User that initiated the flow when one is available. |
type | Verification purpose. |
channel | Delivery channel identifier. |
to | Normalized recipient. |
code | Encrypted credential material; never expose it. |
attemps | Attempt counter. The misspelling is a literal model field. |
times | Delivery counter for the current record. |
send_data | Optional structured delivery data. |
last_sent_at | Last delivery timestamp. |
The full storage model is not a promise that every field appears in a public response.
Code types
If available, the operation validates types 1 through 5:
| Value | Meaning described here |
|---|---|
1 | General |
2 | Cellphone verification |
3 | Email verification |
4 | One-time password |
5 | Deleted-action verification |
Use only a type documented by the operation consuming the code.
Delivery channels
If available, the operation validates channel values 1 through 8:
| Value | If available, the operation |
|---|---|
1 | |
2 | SMS through configured Twilio delivery |
3 | Voice through configured Twilio delivery |
4 | WhatsApp through configured Twilio delivery |
5–8 | Plugin-defined hooks; meaning depends on project configuration |
Earlier documentation labeled only channel 5 as custom. If available, the operation routes every channel above 4 through a channel-specific plugin hook, so this guide does not invent names for values 5–8.
Generating a code is unauthenticated in the current public operation contract but remains subject to project configuration and rate limits. Verifying a code requires an accepted API key or bearer session in the current public contract. The API reference defines these authentication requirements.
For the user flow that consumes verification codes, see the Verify a user guide. The linked guide explains the related user-verification flow.