Skip to main content

Verify an email-OTP code (external integration)

External-integration twin of PostHelpdeskVerifyEmailVerify. Re-runs the IdP-sourced-email deny-gate before reporting success, so an identity removed from the verification source between initiate and verify cannot complete verification.

Header Parameters
  • SlashID-OrgID string required

    The organization ID

    Example: af5fbd30-7ce7-4548-8b30-4cd59cb2aba1
Request Body required
  • verification_id string required

    The verification_id returned by external email-initiate

  • code string required

    Possible values: Value must match regular expression ^\d{6}$

    The 6-digit code sent to the target email

  • connection_id string required

    The external identity connection ID (must match the one used at initiate)

  • operator object required
  • email email required

    The human operating the integration (e.g. the ServiceNow agent). MUST be derived server-side by the integration (ServiceNow: gs.getUser().getEmail()), never supplied by its own client. Resolved to a SlashID console person holding a verifier role; 403 if it does not resolve or lacks the role.

  • assertion string required

    Possible values: [integration_asserted, idp_verified]

    How the operator identity was established. integration_asserted — the calling integration vouches for it under its own API credential; idp_verified — proven to SlashID directly. Recorded on every attempt so that a later move to per-agent authentication does not change what historical audit rows meant. Only integration_asserted is accepted today.

Responses

Verification result


Schema
  • meta object
  • pagination object
  • limit integer
  • offset integer
  • total_count int64
  • cursor_pagination object

    Cursors are opaque. Follow the tokens the server returns; never construct, parse or modify one.

  • limit integer
  • next_cursor string

    Opaque token addressing the next page. Absent on the last page.

  • prev_cursor string

    Opaque token addressing the previous page. Absent on the first page.

  • last_cursor string

    Opaque token addressing the final page directly, so a client can jump to the end without a total count.

  • total_count int64

    Total number of matching items. Returned on the FIRST page only; clients cache it for the remainder of the walk.

  • errors object[]
  • httpcode integer
  • message string
  • result object
  • verified boolean

    Whether the email-OTP code was correct