Skip to main content

Worked request and response samples

Copy a request body as written, substitute your own ids, and compare the response envelope. Errors follow Devotel Orbit’s { error, meta } envelope, shown once below under Error envelope.

Send a verification code

POST /api/v1/verify/send
Pick the channel you deliver the code on, and hold onto the returned verification_id for the check call. Request

Check a code

POST /api/v1/verify/check
Send the verification_id from the send call and the code the user typed. Request

Error envelope

An expired or wrong code returns 422 with VALIDATION_ERROR; repeated wrong codes are rate-limited.
422

Gate a verification on identity signals

POST /api/v1/verify/fraud-gate
Decide whether to trust a number before sending the OTP. One call fuses the three carrier-asserted takeover signals — SIM-swap recency, port-event (number recycling), and silent network auth possession — into a single allow / review / deny decision. Request
Add a device-bound access_token (from the three-legged Silent Auth flow) to also check possession, and pass any backups you already hold — number_recycled, roaming, reputation_risk_level, call_forwarding_unconditional. Operator-asserted results always win over the backups you supply; when no carrier integration is configured, the gate still answers from your backups and lists the operator signals under signals_unavailable.
The three headline signals are audited in headline_signals so you can tell “SIM-swap came back clean” apart from “SIM-swap was not evaluated”. A missing signal always contributes zero risk in either direction — you can tune the fusion per request with weights (0-100 per signal) and thresholds (the review / deny cut points on the 0-100 score). Nothing is ever sent to the subscriber by this call; it is a read-only network check.