Verify Flow
Verify an Authsignal flow for a given action by passing a challengeToken obtained from a pre-built UI redirect or client SDK. This will return the current state of the flow. If the flow has been completed successfully and an app client has been configured then the response will include an access token and refresh token.
curl --request POST \
--url https://api.authsignal.com/v1/flows/verify \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"actionCode": "signIn",
"challengeToken": "e252f2b5-a872-46e8-a018-c6e63989d311"
}
'import requests
url = "https://api.authsignal.com/v1/flows/verify"
payload = {
"actionCode": "signIn",
"challengeToken": "e252f2b5-a872-46e8-a018-c6e63989d311"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({actionCode: 'signIn', challengeToken: 'e252f2b5-a872-46e8-a018-c6e63989d311'})
};
fetch('https://api.authsignal.com/v1/flows/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.authsignal.com/v1/flows/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'actionCode' => 'signIn',
'challengeToken' => 'e252f2b5-a872-46e8-a018-c6e63989d311'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.authsignal.com/v1/flows/verify"
payload := strings.NewReader("{\n \"actionCode\": \"signIn\",\n \"challengeToken\": \"e252f2b5-a872-46e8-a018-c6e63989d311\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.authsignal.com/v1/flows/verify")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"actionCode\": \"signIn\",\n \"challengeToken\": \"e252f2b5-a872-46e8-a018-c6e63989d311\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.authsignal.com/v1/flows/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"actionCode\": \"signIn\",\n \"challengeToken\": \"e252f2b5-a872-46e8-a018-c6e63989d311\"\n}"
response = http.request(request)
puts response.read_body{
"action": {
"state": "CHALLENGE_REQUIRED",
"completedSteps": [
{
"stepType": "VERIFICATION_REQUIRED",
"verificationMethod": "SMS",
"userAuthenticatorId": "<string>"
}
],
"nextStep": {
"stepType": "VERIFICATION_REQUIRED",
"verificationMethods": [
"AUTHENTICATOR_APP"
]
}
},
"session": {
"accessToken": "<string>",
"refreshToken": "<string>"
},
"user": {
"userId": "<string>",
"authenticators": [
{
"userAuthenticatorId": "<string>",
"verificationMethod": "AUTHENTICATOR_APP",
"email": "<string>",
"phoneNumber": "<string>",
"username": "<string>",
"displayName": "<string>"
}
],
"email": "<string>",
"phoneNumber": "<string>",
"username": "<string>",
"displayName": "<string>"
}
}{
"error": "<string>",
"errorDescription": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>"
}Authorizations
Use your Authsignal Server API secret key as the username and leave the password empty. The secret key can be found in the API Keys section of the Authsignal Portal settings page.
Body
The same action code passed to startFlow. Used to ensure verification is being performed for the correct action.
The latest challengeToken issued for this flow. If integrating using the pre-built UI, you can obtain this from the 'challenge_token' query parameter when handling the redirect back to your app. If integrating using SDKs, you should use the latest value returned by the SDK.
Was this page helpful?
curl --request POST \
--url https://api.authsignal.com/v1/flows/verify \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"actionCode": "signIn",
"challengeToken": "e252f2b5-a872-46e8-a018-c6e63989d311"
}
'import requests
url = "https://api.authsignal.com/v1/flows/verify"
payload = {
"actionCode": "signIn",
"challengeToken": "e252f2b5-a872-46e8-a018-c6e63989d311"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({actionCode: 'signIn', challengeToken: 'e252f2b5-a872-46e8-a018-c6e63989d311'})
};
fetch('https://api.authsignal.com/v1/flows/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.authsignal.com/v1/flows/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'actionCode' => 'signIn',
'challengeToken' => 'e252f2b5-a872-46e8-a018-c6e63989d311'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.authsignal.com/v1/flows/verify"
payload := strings.NewReader("{\n \"actionCode\": \"signIn\",\n \"challengeToken\": \"e252f2b5-a872-46e8-a018-c6e63989d311\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.authsignal.com/v1/flows/verify")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"actionCode\": \"signIn\",\n \"challengeToken\": \"e252f2b5-a872-46e8-a018-c6e63989d311\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.authsignal.com/v1/flows/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"actionCode\": \"signIn\",\n \"challengeToken\": \"e252f2b5-a872-46e8-a018-c6e63989d311\"\n}"
response = http.request(request)
puts response.read_body{
"action": {
"state": "CHALLENGE_REQUIRED",
"completedSteps": [
{
"stepType": "VERIFICATION_REQUIRED",
"verificationMethod": "SMS",
"userAuthenticatorId": "<string>"
}
],
"nextStep": {
"stepType": "VERIFICATION_REQUIRED",
"verificationMethods": [
"AUTHENTICATOR_APP"
]
}
},
"session": {
"accessToken": "<string>",
"refreshToken": "<string>"
},
"user": {
"userId": "<string>",
"authenticators": [
{
"userAuthenticatorId": "<string>",
"verificationMethod": "AUTHENTICATOR_APP",
"email": "<string>",
"phoneNumber": "<string>",
"username": "<string>",
"displayName": "<string>"
}
],
"email": "<string>",
"phoneNumber": "<string>",
"username": "<string>",
"displayName": "<string>"
}
}{
"error": "<string>",
"errorDescription": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>"
}
