---
title: "Guest Phone Check"
method: POST
path: "/v1/guest/phone-check"
tags: ["guest"]
---

# Guest Phone Check

`POST /v1/guest/phone-check`

Is this a real mobile? Asked BEFORE a code is texted to it.

Owner, 2026-09-02: "we use VERIFIER first before sending smth to the phone
number pls!!!" A typo costs a message and leaves somebody watching a
handset that will never buzz; a landline typed into a field asking for a
mobile can never be right at all. Neither is worth an SMS.

PUBLIC, LIKE THE DOOR ABOVE IT, AND FOR THE SAME REASON. The surface that
asks is the claim card on a public sample (`/samples/<slug>`), and a
visitor's token is refused every unsafe method before a handler runs
(`dependencies.principal`) — so a route that demanded one would have to be
a GET, and a GET puts the number in the URL and therefore in every access
log between here and the browser.

THE ANSWER IS THREE FIELDS AND CARRIES NOTHING ABOUT THE PERSON. carrier
returns the carrier's name; we drop it. `national_format` is the number the
caller already typed, spelled back the way the country spells it, which is
the one thing a screen needs to show them.

## Request body

- GuestPhoneCheckRequest
  - `phone` string

## Response `200`

Successful Response

- object

## Other responses

- `422` — Validation Error

## Changes

> 32 revisions in range; 1 not diffed.

- **2026-09-03** `c48c4f626ab0` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/stormy/apis/stormy-control-plane/changes/v1/guest/phone-check/post.md)

---

[API](https://skmtc.dev/stormy/apis/stormy-control-plane.md) · [All operations](https://skmtc.dev/stormy/apis/stormy-control-plane/llms.txt) · [OpenAPI document](https://skmtc.dev/stormy/apis/stormy-control-plane/revisions/b09e3c4ee2af?raw)
