K-OTP

발급 이력 목록

GET /v1/issues

GET https://api.k-otp.dev/v1/issues

개요

Returns a PII-free dashboard projection of OTP issues. The tenant is always derived from the bearer credential. Phone numbers, OTP material, provider payloads, idempotency keys, and free-form metadata are never included.

Results are ordered newest first (createdAt descending, ties broken by id) and keyset-paginated. Pass limit (1-100, default 50) and, for subsequent pages, the opaque cursor returned as nextCursor; nextCursor is omitted on the last page. Cursors are bound to the endpoint that issued them and must be sent unchanged. Keep the same filters while paging.

Optional createdFrom/createdTo (RFC 3339 date-time) select the half-open range [createdFrom, createdTo); when both are given createdFrom must be earlier than createdTo. verificationStatus filters by effective status: issued matches only unexpired issues, and expired also includes issued rows whose expiry has passed.

deliveryStatus is read from the delivery tracker and falls back to unknown if the tracker is temporarily unavailable.

Requires an sk_ secret key; pk_ public keys are rejected with 403.

인증

허용 키필요 scope대체 허용 scope
sk_otp:dashboard:readotp:read, *

파라미터

이름위치타입필수설명
limitqueryintegerPage size: 1-100 items. Defaults to 50 when omitted.
cursorquerystringnextCursor from the previous page.
verificationStatusquery"expired" | "issued" | "max_attempts" | "replaced" | "verified"Filter by effective verification status. issued matches only unexpired issues; expired also matches issued rows whose expiry has passed.
createdFromquerystring (date-time)Inclusive lower bound on createdAt.
createdToquerystring (date-time)Exclusive upper bound on createdAt; must be later than createdFrom.

응답 (200)

One page of issues, newest first.

필드타입필수설명
itemsobject[]예
nextCursorstringCursor for the next page; absent on the last page.

오류 응답

모든 오류는 { defined, code, status, message, data? } 형태입니다. 자세한 내용은 오류를 참고하세요.

상태code설명
400BAD_REQUESTinvalid query, limit outside 1-100, malformed cursor, a cursor issued by a different endpoint, or createdFrom not earlier than createdTo.
401UNAUTHORIZEDthe Authorization: Bearer credential is missing, malformed, inactive, or rejected by introspection.
403FORBIDDENthe credential lacks otp:dashboard:read (or an accepted alias), or a pk_ public key was used. Public keys are limited to issue/verify.
409CONFLICTthe request conflicts with the current state of the resource.
500INTERNAL_SERVER_ERRORunexpected server failure. Undefined errors (defined: false) use the same envelope.
503SERVICE_UNAVAILABLEcredential introspection or a downstream dependency is temporarily unavailable. Retry with backoff.

요청 예시

curl "https://api.k-otp.dev/v1/issues" \
  -H "Authorization: Bearer $KOTP_SECRET_KEY"

이 페이지의 내용