Start Flow
API schema
userId, email, phoneNumber or username.
Send the user to the returned challengeUrl to complete each step in the pre-built UI. When they finish, the pre-built UI redirects back to your redirectUrl with a challenge_token.
Verify Flow
API schema
CHALLENGE_SUCCEEDED once the user has completed every required step, or CHALLENGE_FAILED if the flow ended in a Block outcome or the user couldn’t complete a step. To get session tokens, enable the JWKS URL for your tenant and pass an app client’s ID as clientId to Start Flow. Verify Flow then returns access and refresh tokens when the action state is CHALLENGE_SUCCEEDED and the user completed at least one verification step. A flow that only enrolls a method doesn’t return tokens. See Session management.

