Skip to main content

Codes model

Codes support one-time verification workflows such as user verification and one-time passwords. A code is sensitive, short-lived workflow data; never place a real code or recipient in documentation or logs.

Public operations​

The current public API Reference contains these code operations:

ActionMethodResourcePurpose
Generate a codePOST/codes/generateValidate delivery data, create or reuse a code under rate limits, and dispatch delivery.
Verify a codeGET/codes/verifyVerify a code using query parameters.
Verify a codePOST/codes/verifyVerify a code using a JSON request body.

The current public API reference does not document GET /codes/generate; its public availability is unconfirmed.

The operation guide specifies request fields, required values, security, responses, and errors.

Model fields​

The model described here contains these workflow fields:

FieldPurpose
idNumeric record identifier.
sender_idUser that initiated the flow when one is available.
typeVerification purpose.
channelDelivery channel identifier.
toNormalized recipient.
codeEncrypted credential material; never expose it.
attempsAttempt counter. The misspelling is a literal model field.
timesDelivery counter for the current record.
send_dataOptional structured delivery data.
last_sent_atLast delivery timestamp.

The full storage model is not a promise that every field appears in a public response.

Code types​

If available, the operation validates types 1 through 5:

ValueMeaning described here
1General
2Cellphone verification
3Email verification
4One-time password
5Deleted-action verification

Use only a type documented by the operation consuming the code.

Delivery channels​

If available, the operation validates channel values 1 through 8:

ValueIf available, the operation
1Email
2SMS through configured Twilio delivery
3Voice through configured Twilio delivery
4WhatsApp through configured Twilio delivery
5–8Plugin-defined hooks; meaning depends on project configuration

Earlier documentation labeled only channel 5 as custom. If available, the operation routes every channel above 4 through a channel-specific plugin hook, so this guide does not invent names for values 5–8.

Generating a code is unauthenticated in the current public operation contract but remains subject to project configuration and rate limits. Verifying a code requires an accepted API key or bearer session in the current public contract. The API reference defines these authentication requirements.

For the user flow that consumes verification codes, see the Verify a user guide. The linked guide explains the related user-verification flow.