Verify an email address
Redeems the single-use JWT carried by a verification email and marks the actor's email as verified. The token is HMAC-signed, purpose-scoped, expires after a short TTL, and is consumed on first use (jti anti-replay). Re-clicking a consumed link on an already-verified account succeeds (idempotent).
/auth/verify-emailRedeems the single-use JWT carried by a verification email and marks the actor's email as verified. The token is HMAC-signed, purpose-scoped, expires after a short TTL, and is consumed on first use (jti anti-replay). Re-clicking a consumed link on an already-verified account succeeds (idempotent).
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Request body for POST /auth/verify-email.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/verify-email" \ -H "Content-Type: application/json" \ -d '{ "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." }'{
"code": 200,
"message": "string",
"data": {},
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"pagination": {
"page": 1,
"limit": 1,
"total": 0,
"has_next": true,
"has_prev": true,
"next_page": 0,
"prev_page": 0
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "string"
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "IdentityX"
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "IdentityX"
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "IdentityX"
}Register a user POST
Registers the credential pair, either as an IdentityX client (no `project_id`) or as a client of a project that consumes IdentityX for authn (pass `project_id`). Returns 201 with an empty body — the caller then logs in via `/auth/login`.
Resend the verification email POST
Mints a fresh verification link and emails it to the given address. Always returns 200 — unknown emails and already-verified accounts are silent no-ops, so the endpoint does not leak which emails are registered.