Worked request and response samples
Copy a request body as written, substitute your own ids, and compare the response envelope. Errors follow Devotel Orbit’s{ error, meta } envelope, shown once below under Error envelope.
Send a verification code
POST /api/v1/verify/sendverification_id for the check call.
Request
Check a code
POST /api/v1/verify/checkverification_id from the send call and the code the user typed.
Request
Error envelope
An expired or wrong code returns422 with VALIDATION_ERROR; repeated wrong codes are rate-limited.
422
Gate a verification on identity signals
POST /api/v1/verify/fraud-gateallow / review / deny decision.
Request
access_token (from the three-legged Silent Auth flow) to also check possession, and pass any backups you already hold — number_recycled, roaming, reputation_risk_level, call_forwarding_unconditional. Operator-asserted results always win over the backups you supply; when no carrier integration is configured, the gate still answers from your backups and lists the operator signals under signals_unavailable.
headline_signals so you can tell “SIM-swap came back clean” apart from “SIM-swap was not evaluated”. A missing signal always contributes zero risk in either direction — you can tune the fusion per request with weights (0-100 per signal) and thresholds (the review / deny cut points on the 0-100 score). Nothing is ever sent to the subscriber by this call; it is a read-only network check.