K-OTP

List available OTP templates

GET /v1/templates

GET https://api.k-otp.dev/v1/templates

Overview

Returns the whitelisted message templates that POST /issue accepts via templateId, plus the default template id used when templateId is omitted. The list is small and not paginated. Every template body contains the #{code} placeholder; new templates are registered operationally, not through the API.

Requires an sk_ secret key; pk_ public keys are rejected with 403.

Authentication

Accepted keysRequired scopeAlso accepted
sk_otp:templatesotp:read, *

Response (200)

All available templates.

FieldTypeRequiredDescription
defaultTemplateIdstringyesTemplate used when POST /v1/issue omits templateId.
templatesobject[]yes
notestringyesHuman-readable policy note.

Error responses

Every error uses the { defined, code, status, message, data? } envelope. See Errors.

StatuscodeDescription
400BAD_REQUESTthe request failed input validation. message describes the first failing constraint.
401UNAUTHORIZEDthe Authorization: Bearer credential is missing, malformed, inactive, or rejected by introspection.
403FORBIDDENthe credential lacks otp:templates (or an accepted alias), or a pk_ public key was used. Public keys are limited to issue/verify.
409CONFLICTthe request conflicts with the current state of the resource.
500INTERNAL_SERVER_ERRORunexpected server failure. Undefined errors (defined: false) use the same envelope.
503SERVICE_UNAVAILABLEcredential introspection or a downstream dependency is temporarily unavailable. Retry with backoff.

Example request

curl "https://api.k-otp.dev/v1/templates" \
  -H "Authorization: Bearer $KOTP_SECRET_KEY"

On this page