> ## Documentation Index
> Fetch the complete documentation index at: https://docs.authsignal.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify Flow

> Verify an Authsignal flow for a given action by passing a challengeToken obtained from a pre-built UI redirect or client SDK. This will return the current state of the flow. If the flow has been completed successfully and an app client has been configured then the response will include an access token and refresh token.



## OpenAPI

````yaml server-api POST /flows/verify
openapi: 3.0.0
info:
  description: Authsignal's Server API.
  version: 1.0.0
  title: Server API
  termsOfService: https://www.authsignal.com/legal/terms-of-service
  contact:
    email: hello@authsignal.com
servers:
  - url: https://api.authsignal.com/v1
  - url: https://au.api.authsignal.com/v1
  - url: https://eu.api.authsignal.com/v1
  - url: https://ca.api.authsignal.com/v1
  - url: https://uk.api.authsignal.com/v1
security:
  - basicAuth: []
tags:
  - name: users
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: challenge
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: authenticator configurations
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: actions
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: query
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: email
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: sms
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: verify
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: challenges
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: sessions
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: devices
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
  - name: flows
    description: ''
    externalDocs:
      description: Find out more
      url: https://docs.authsignal.com
externalDocs:
  description: Find out more about Authsignal
  url: https://docs.authsignal.com
paths:
  /flows/verify:
    post:
      tags:
        - flows
      summary: Verify flow
      description: >-
        Verify an Authsignal flow for a given action by passing a challengeToken
        obtained from a pre-built UI redirect or client SDK. This will return
        the current state of the flow. If the flow has been completed
        successfully and an app client has been configured then the response
        will include an access token and refresh token.
      operationId: verifyFlow
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                actionCode:
                  type: string
                  description: >-
                    The same action code passed to startFlow. Used to ensure
                    verification is being performed for the correct action.
                challengeToken:
                  type: string
                  description: >-
                    The latest challengeToken issued for this flow. If
                    integrating using the pre-built UI, you can obtain this from
                    the 'challenge_token' query parameter when handling the
                    redirect back to your app. If integrating using SDKs, you
                    should use the latest value returned by the SDK.
              required:
                - actionCode
                - challengeToken
            example:
              actionCode: signIn
              challengeToken: e252f2b5-a872-46e8-a018-c6e63989d311
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  action:
                    $ref: '#/components/schemas/FlowAction'
                  session:
                    $ref: '#/components/schemas/SessionResponse'
                  user:
                    $ref: '#/components/schemas/FlowUser'
                required:
                  - action
        '400':
          $ref: '#/components/responses/InvalidRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    FlowAction:
      type: object
      properties:
        state:
          $ref: '#/components/schemas/FlowState'
        completedSteps:
          type: array
          items:
            $ref: '#/components/schemas/FlowCompletedActionStep'
          description: Steps already completed in this flow.
        nextStep:
          allOf:
            - $ref: '#/components/schemas/FlowActionStep'
          description: >-
            The next step in the flow which must be completed. Absent if there
            are no more steps.
      required:
        - state
        - completedSteps
    SessionResponse:
      type: object
      properties:
        accessToken:
          type: string
          description: An access token which can be used to authenticate requests.
        refreshToken:
          type: string
          description: >-
            A refresh token which can be exchanged for a new access token and
            refresh token.
      required:
        - accessToken
        - refreshToken
    FlowUser:
      type: object
      properties:
        userId:
          type: string
        email:
          type: string
        phoneNumber:
          type: string
        username:
          type: string
        displayName:
          type: string
        authenticators:
          type: array
          items:
            $ref: '#/components/schemas/FlowUserAuthenticator'
      required:
        - userId
        - authenticators
    FlowState:
      type: string
      enum:
        - CHALLENGE_REQUIRED
        - CHALLENGE_SUCCEEDED
        - CHALLENGE_FAILED
      description: >-
        The current state of the flow. Indicates whether the flow has succeeded,
        failed, or is still awaiting a challenge.
    FlowCompletedActionStep:
      type: object
      properties:
        stepType:
          $ref: '#/components/schemas/FlowActionStepType'
        verificationMethod:
          $ref: '#/components/schemas/VerificationMethod'
        userAuthenticatorId:
          type: string
          description: The ID of the authenticator used to complete this step.
      required:
        - stepType
        - verificationMethod
        - userAuthenticatorId
    FlowActionStep:
      type: object
      properties:
        stepType:
          $ref: '#/components/schemas/FlowActionStepType'
        verificationMethods:
          type: array
          items:
            $ref: '#/components/schemas/FlowVerificationMethod'
          description: >-
            The verification methods that can be used to complete this step.
            Flows only currently support a subset of verification methods.
      required:
        - stepType
        - verificationMethods
    FlowUserAuthenticator:
      type: object
      properties:
        userAuthenticatorId:
          type: string
        verificationMethod:
          $ref: '#/components/schemas/FlowVerificationMethod'
        email:
          type: string
        phoneNumber:
          type: string
        username:
          type: string
        displayName:
          type: string
      required:
        - userAuthenticatorId
        - verificationMethod
    Error:
      type: object
      properties:
        error:
          type: string
        errorDescription:
          type: string
      required:
        - error
    FlowActionStepType:
      type: string
      enum:
        - VERIFICATION_REQUIRED
        - ENROLLMENT_REQUIRED
        - ENROLLMENT_OPTIONAL
      description: >-
        Whether the next step requires the user to verify with an existing
        authenticator, or enroll a new one.
    VerificationMethod:
      type: string
      enum:
        - SMS
        - AUTHENTICATOR_APP
        - EMAIL_MAGIC_LINK
        - EMAIL_OTP
        - PUSH
        - DEVICE
        - SECURITY_KEY
        - PASSKEY
        - VERIFF
        - IPROOV
        - PALM_BIOMETRICS_RR
        - IDVERSE
        - WHATSAPP
    FlowVerificationMethod:
      type: string
      enum:
        - AUTHENTICATOR_APP
        - EMAIL_OTP
        - PASSKEY
        - SMS
        - WHATSAPP
  responses:
    InvalidRequest:
      description: Invalid Request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: >-
        Use your Authsignal Server API secret key as the username and leave the
        password empty. The secret key can be found in the API Keys section of
        the Authsignal Portal settings page.

````