K-OTP

Introduction

An OTP API that sends verification codes over SMS and KakaoTalk AlimTalk and verifies them

K-OTP lets you issue → deliver → verify phone verification codes (OTP) with two API calls. K-OTP generates the code, sends it by SMS or KakaoTalk AlimTalk, enforces expiry and attempt limits, deduplicates retries, and settles credits.

How it works

 Your server / browser          K-OTP API                     End user's phone
 ─────────────────────          ─────────                     ────────────────
 1. POST /v1/issue  ─────────▶  generate 6-digit code (hash only)
    (Idempotency-Key)           reserve credit + queue delivery
                     ◀───────── { issueId, expiresAt, ... }
                                2. send SMS or AlimTalk ─────▶  "[K-OTP] 인증번호는 123456..."
 3. POST /v1/verify ─────────▶  check issueId + code
    { issueId, code }           (expiry, max attempts, one-time)
                     ◀───────── { verified: true }
  1. Issue — your service sends a phone number and a purpose to POST /v1/issue. K-OTP generates a 6-digit code server-side, reserves credit, and queues delivery. The response contains an issueId, never the code.
  2. Deliver — K-OTP sends the code by SMS (default) or AlimTalk. Delivery is tracked asynchronously; check it with GET /v1/status.
  3. Verify — send the code the user typed together with the issueId to POST /v1/verify. The response is always 200; read verified and, on failure, reasonCode.

Key concepts

ConceptDescription
AppThe unit you create in the console. Keys, the credit wallet, and issue history belong to an app. All keys of an app share one wallet.
Keyspk_ (public, browser, issue/verify only) and sk_ (secret, server only). See Authentication.
IssueOne issued code, identified by issueId. Expires after 3 minutes and allows 5 verification attempts by default.
Idempotency keyThe Idempotency-Key every issue request needs. It prevents duplicate sends and debits on retry. See Idempotency & retries.
ChannelsSMS or KakaoTalk AlimTalk. Failed AlimTalk sends fall back to SMS automatically. See Channels and failover.
CreditsPrepaid units for sending: every send costs 1 credit, failover included. Issues are rejected with 402 when credit runs out. See Credits & billing.

URLs

PurposeURL
API base URLhttps://api.k-otp.dev/v1
Interactive API referencehttps://api.k-otp.dev/docs
OpenAPI spechttps://api.k-otp.dev/openapi/v1.json
Consolehttps://app.k-otp.dev

Next steps

On this page