> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://commify.ferndocs.com/one-time-passcodes/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://commify.ferndocs.com/_mcp/server. # One-time passcodes The OTP endpoints generate, deliver and verify one-time passcodes, so you don't have to store codes yourself. ### Request a passcode Call [Request OTP](/api-reference/otp/request-otp) with the recipient and how long the code should remain valid. ```bash curl -X POST http://gateway-api.e97e9e55a5d242f9a139.uksouth.aksapp.io/v2/otps \ -H "X-API-Key: $COMMIFY_API_KEY" \ -H "AccountReference: EX0000000" \ -H "Content-Type: application/json" \ -d '{ "recipient": "447700900000", "channel": "SMS", "from": "Commify", "validitySeconds": 300 }' ``` The response includes the `messageId` of the passcode message and when the code `expiresAt`. ### Verify the passcode When the user enters the code, send it to [Verify OTP](/api-reference/otp/verify-otp) along with the same recipient. ```bash curl -X POST http://gateway-api.e97e9e55a5d242f9a139.uksouth.aksapp.io/v2/otps/verify \ -H "X-API-Key: $COMMIFY_API_KEY" \ -H "AccountReference: EX0000000" \ -H "Content-Type: application/json" \ -d '{ "recipient": "447700900000", "otp": "123456" }' ``` > **Tip** > > Keep `validitySeconds` short (a few minutes) and rate-limit OTP requests per recipient to reduce fraud and cost. > Verify users with OTPs sent over SMS