Account Recovery
Verify account recovery
POST
/api/v1/users/recovery/verifyRestores a deleted account using the code from POST /recovery/request and signs the user back in.
No authentication required
Credential check — tight, feeds automatic IP blocking
Body parameters
emailstringrequired | Email address of the deleted account. |
codestringrequired | The recovery code from the email. |
deviceNamestring | Human-readable device label for the new session. |
localestring | en or fr. |
Notes
- If two-factor authentication is enabled, the response is { requiresTotp: true, pendingToken } instead — finish with POST /auth/login/totp.
Request
curl --request POST \
--url https://api.swiftgoma.com/api/v1/users/recovery/verify \
--header 'Content-Type: application/json' \
--data '{
"email": "aline@example.com",
"code": "482913",
"deviceName": "Chrome on macOS",
"locale": "fr"
}'200Example response
{
"success": true,
"data": {
"user": {
"id": "3f2a1c9e-7b41-4e2a-9c31-8e6b2d4f10aa",
"name": "Aline Mapendo",
"role": "BUYER",
"email": "aline@example.com",
"isEmailVerified": true,
"phone": "243812345678",
"isPhoneVerified": true,
"preferredCurrency": "USD",
"avatarUrl": "https://res.cloudinary.com/dx3wclabo/image/upload/v1/avatars/aline.jpg",
"isBlocked": false,
"createdAt": "2026-01-14T10:32:00.000Z"
}
}
}