CorebanqCorebanq Developer Docs
Usersv1Credentials

Validate credential

Confirm a credential with its one-time code. A `cred_id` that names nothing, or names a credential belonging to somebody else, is refused exactly as a wrong code is rather than reported as missing, and never reaches that credential's attempt budget. The same holds for a credential whose value another account has already confirmed. `400 otp_m.otp_invalid`, `400 otp_m.otp_expired` and `429 otp_m.cooling_period_active` are therefore the whole refusal vocabulary of this endpoint.

POST
/v1/users/credentials/validate

Authorization

bearerAuth
AuthorizationBearer <token>

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

ValidateCredentialInput: the credential is addressed by user_id and cred_id, not by credential_id.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v1/users/credentials/validate" \  -H "Content-Type: application/json" \  -d '{    "user_id": "a169451c-8525-4352-b8ca-070dd449a1a5",    "cred_id": "0a7f530e-cca8-4c90-8518-dced55521236",    "otp": "string"  }'
{
  "message": "Your account has been successfully verified and activated.",
  "status": "success"
}

{
  "message": "Invalid OTP. 2 attempt(s) left",
  "status": "invalid"
}

{
  "status": 401,
  "message": "Unauthorized",
  "code": "common.unauthorized",
  "class": "business"
}
{
  "status": 403,
  "message": "No access to the record",
  "code": "common.rbac_no_rec_access",
  "class": "business"
}
{
  "message": "Credential already exists",
  "status": "duplicate"
}

{
  "message": "In cooling period for 1 minute, 60 second(s) left",
  "status": "cooling",
  "wait": 60
}

{
  "message": "An error occurred while verifying the code",
  "status": "error"
}

{
  "overall_status": "unhealthy",
  "message": "Service is shutting down",
  "timestamp": "2026-08-27T15:04:05Z"
}