Confirm a sender address with its code
Completes the claim. 200 with verified_at set, after which the
address may appear in an inbox's allowed_senders.
Confirming an already-verified claim is also a 200 with the same
body: a second tab did nothing wrong.
A wrong code is 422 and the detail says how many attempts remain.
Five wrong codes lock the claim; the way out is a fresh
POST /v1/verified-senders, not a sixth guess. A code expires 15
minutes after it was sent.
Requires a user-delegated token.
Path parameters
id string<uuid> required The claim's UUID, as returned by POST /v1/verified-senders.
Request body
Content type: application/json
code string required The six digits from the email. Five wrong guesses lock the claim.
Responses
Errors follow the RFC 7807 problem format — see the error reference.
id string<uuid> required email string required The address, lower-cased. PII.
status string enum required locked means five wrong codes; the way out is a fresh POST /v1/verified-senders, not a sixth guess.
One of: pending, locked, verified
code_expires_at string<date-time> optional When the outstanding code lapses, 15 minutes after it was sent. Absent on a verified claim — confirming clears the code.
verified_at string<date-time> optional Present once the code came back. This is what the mint path asks about.
created_at string<date-time> required code: invalid_scope), or it is bound to the test environment and this operation is irreversible (code: test_environment_forbidden). Branch on code: the first is fixed by granting the scope, the second only by using a live credential. See the "Live and test credentials" section of the API description. application/problem+json validation_failed Problem. When the refusal is about a
reference — a segment key, template slug, topic or attribute name the
organization does not have — it additionally carries validation_code,
field, line/column, missing, candidates and next_step, so a
client can correct the call without a second round of guessing. See
ValidationProblem.
application/problem+json code is internal_error. The
request_id field can be quoted to SendOps support to investigate.
application/problem+json