Login
Verify a passwordless login code
POST
/api/v1/auth/login/verify-otpCompletes passwordless login using the code from POST /login/request-otp.
No authentication required
Credential check — tight, feeds automatic IP blocking
Body parameters
emailstringrequired | Account email address. |
codestringrequired | The login code from the email. |
deviceNamestring | Human-readable device label for the new session. |
Possible errors
| 401 | OTP_INVALID | Code de vérification invalide ou expiré. |
Notes
- If two-factor authentication is enabled, the response is { requiresTotp: true, pendingToken } instead — pass pendingToken to POST /login/totp.
- On web, tokens are set as httpOnly cookies; on mobile, they're included in the response body.
Request
curl --request POST \
--url https://api.swiftgoma.com/api/v1/auth/login/verify-otp \
--header 'Content-Type: application/json' \
--data '{
"email": "aline@example.com",
"code": "482913",
"deviceName": "Chrome on macOS"
}'200Example response
{
"success": true,
"data": {
"user": {
"id": "3f2a1c9e-7b41-4e2a-9c31-8e6b2d4f10aa",
"name": "Aline Mapendo",
"role": "BUYER",
"email": "aline@example.com",
"isEmailVerified": true,
"phone": "243812345678",
"isPhoneVerified": false,
"createdAt": "2026-01-14T10:32:00.000Z"
}
}
}