Skip to main content
POST
Verify password or bound Apple token and MFA
Preview contract. Production availability remains subject to activation and release qualification. Examples are synthetic; the documentation cannot submit requests.

Authorization

Same authenticated Settings session and pending operation.

Behavior

Proof has exactly one of password or apple_token, with mfa_code when required. Apple proof must match the nonce/audience and already-linked subject. The approval is purpose/payload-bound and consumed once during issuance. Five proof attempts share the approval budget. This is a session-owned application contract, not an ordinary API-key endpoint. Use Settings → Integrations. The public API base URL does not grant session access.

JSON body example

The following shows the request shape, not live credentials or executable market defaults. Replace timestamps only when creating a new reviewed intent; never mutate them on a command retry.
The displayed password and MFA value are nonfunctional placeholders. Never store real account authentication proof in source code, public documentation or an integration client. This payload is sent only by the authenticated Settings flow.

Response and errors

The generated response schema below is the wire contract. Preserve fixed-point strings, nullable fields and endpoint-specific envelopes. Inspect HTTP status and Content-Type before decoding failures; reused trading routes may return JSON or plain text. Authentication, entitlement and exact link/instrument restrictions apply in addition to endpoint validation. See errors and recovery. Do not automatically repeat a mutation after transport ambiguity. Trading commands reuse the exact immutable identity; credential issuance and template writes require their documented metadata/read reconciliation. Read the related guide for lifecycle, units and recovery semantics.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
operation_id
string<uuid>
required
proof
object
required

Response

Success

operation_id
string<uuid>
required
approved
any
required
expires_at
integer<int64>
required