v0alpha1

Complete Verification Flow

Use this endpoint to complete a verification flow. This endpoint behaves differently for API and browser flows and has several states:

choose_method expects flow (in the URL query) and email (in the body) to be sent and works with API- and Browser-initiated flows. For API clients and Browser clients with HTTP Header Accept: application/json it either returns a HTTP 200 OK when the form is valid and HTTP 400 OK when the form is invalid and a HTTP 302 Found redirect with a fresh verification flow if the flow was otherwise invalid (e.g. expired). For Browser clients without HTTP Header Accept or with Accept: text/* it returns a HTTP 302 Found redirect to the Verification UI URL with the Verification Flow ID appended. sent_email is the success state after choose_method when using the link method and allows the user to request another verification email. It works for both API and Browser-initiated flows and returns the same responses as the flow in choose_method state. passed_challenge expects a token to be sent in the URL query and given the nature of the flow ("sending a verification link") does not have any API capabilities. The server responds with a HTTP 302 Found redirect either to the Settings UI URL (if the link was valid) and instructs the user to update their password, or a redirect to the Verification UI URL with a new Verification Flow ID which contains an error message that the verification link was invalid.

More information can be found at Ory Kratos Email and Phone Verification Documentation.

post/self-service/verification

Query parameters

flowstring required

The Verification Flow ID

The value for this parameter comes from flow URL Query parameter sent to your application (e.g. /verification?flow=abcde).

tokenstring

Verification Token

The verification token which completes the verification request. If the token is invalid (e.g. expired) an error will be shown to the end-user.

This parameter is usually set in a link and not used by any direct API call.

Request body

csrf_tokenstring

Sending the anti-csrf token is only required for browser login flows.

emailstring required

Email to Verify

Needs to be set when initiating the flow. If the email is a registered verification email, a verification link will be sent. If the email is not known, a email with details on what happened will be sent instead.

format: email

method'link' required

Method supports link only right now.

Response

selfServiceVerificationFlow

activestring

Active, if set, contains the registration method that is being used. It is initially not set.

expires_atstring date-time

ExpiresAt is the time (UTC) when the request expires. If the user still wishes to verify the address, a new request has to be initiated.

idstring uuid4 required
issued_atstring date-time

IssuedAt is the time (UTC) when the request occurred.

request_urlstring

RequestURL is the initial URL that was requested from Ory Kratos. It can be used to forward information contained in the URL's path or query for example.

state'choose_method' | 'sent_email' | 'passed_challenge' required

The state represents the state of the verification flow.

choose_method: ask the user to choose a method (e.g. recover account via email) sent_email: the email has been sent to the user passed_challenge: the request was successful and the recovery challenge was passed.

typestring required

The flow type can either be api or browser.

Example response

{
  "expires_at": "2000-01-23T04:56:07.000+00:00",
  "ui": {
    "nodes": [
      {
        "meta": {
          "label": {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        },
        "messages": [
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          },
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        ],
        "type": "type",
        "group": "group"
      },
      {
        "meta": {
          "label": {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        },
        "messages": [
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          },
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        ],
        "type": "type",
        "group": "group"
      }
    ],
    "method": "method",
    "action": "action",
    "messages": [
      {
        "context": "{}",
        "id": 0,
        "text": "text",
        "type": "type"
      },
      {
        "context": "{}",
        "id": 0,
        "text": "text",
        "type": "type"
      }
    ]
  },
  "active": "active",
  "id": "id",
  "type": "type",
  "issued_at": "2000-01-23T04:56:07.000+00:00",
  "request_url": "request_url"
}

Changes