K-OTP

Get an OTP issue for the authenticated app

GET /v1/issues/{issueId}

GET https://api.k-otp.dev/v1/issues/{issueId}

Overview

Returns the same PII-free projection as GET /issues for a single issue, including billing status and attempt counters. Issue identifiers belonging to other apps are indistinguishable from missing records.

Requires an sk_ secret key; pk_ public keys are rejected with 403.

Authentication

Accepted keysRequired scopeAlso accepted
sk_otp:dashboard:readotp:read, *

Parameters

NameInTypeRequiredDescription
issueIdpathstring (uuid)yesissueId returned by POST /v1/issue.

Response (200)

The issue projection.

FieldTypeRequiredDescription
issueIdstring (uuid)yes
purposestringyes
templateIdstringyes
channel"alimtalk" | "sms"yes
verificationStatus"expired" | "issued" | "max_attempts" | "replaced" | "verified"yesEffective status: an issued row past its expiry is reported as expired.
deliveryStatus"delivered" | "failed" | "queued" | "sent" | "unknown"yesLatest tracked delivery status; unknown when the tracker has no record or is unavailable.
overallStatus"delivered" | "delivery_failed" | "expired" | "in_progress" | "max_attempts" | "pending_lookup" | "replaced" | "verified"yesSame derivation as GET /v1/status.
billingStatus"debit_pending" | "debited" | "release_pending" | "released" | "reserved"yesBilling lifecycle of an issue: credit is reserved at admission, then either debited (debit_pending -> debited) or released (release_pending -> released) once send processing finishes.
debitedAmountintegeryesCredits debited for this issue so far.
currencystringyesCredit unit, currently CREDIT.
expiresAtstring (date-time)Undefined only for legacy records that predate persisted expiry timestamps.
verifiedAtstring (date-time)Present once the issue was verified.
attemptsUsedintegeryes
maxAttemptsintegeryes
attemptsRemainingintegeryes
createdAtstring (date-time)yes
updatedAtstring (date-time)yes

Error responses

Every error uses the { defined, code, status, message, data? } envelope. See Errors.

StatuscodeDescription
400BAD_REQUESTissueId is not a UUID.
401UNAUTHORIZEDthe Authorization: Bearer credential is missing, malformed, inactive, or rejected by introspection.
403FORBIDDENthe credential lacks otp:dashboard:read (or an accepted alias), or a pk_ public key was used. Public keys are limited to issue/verify.
404NOT_FOUNDno issue with this issueId exists for the authenticated app.
409CONFLICTthe request conflicts with the current state of the resource.
500INTERNAL_SERVER_ERRORunexpected server failure. Undefined errors (defined: false) use the same envelope.
503SERVICE_UNAVAILABLEcredential introspection or a downstream dependency is temporarily unavailable. Retry with backoff.

Example request

curl "https://api.k-otp.dev/v1/issues/0192f3c4-8b7a-7c3e-9a51-2f4d6e8b1a90" \
  -H "Authorization: Bearer $KOTP_SECRET_KEY"

On this page