curl --request GET \
--url https://auth.otpless.app/auth/v2/status \
--header 'clientId: <api-key>' \
--header 'clientSecret: <api-key>'import requests
url = "https://auth.otpless.app/auth/v2/status"
headers = {
"clientId": "<api-key>",
"clientSecret": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {clientId: '<api-key>', clientSecret: '<api-key>'}};
fetch('https://auth.otpless.app/auth/v2/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://auth.otpless.app/auth/v2/status",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"clientId: <api-key>",
"clientSecret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://auth.otpless.app/auth/v2/status"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("clientId", "<api-key>")
req.Header.Add("clientSecret", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://auth.otpless.app/auth/v2/status")
.header("clientId", "<api-key>")
.header("clientSecret", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://auth.otpless.app/auth/v2/status")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["clientId"] = '<api-key>'
request["clientSecret"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"auths": [
{
"identityType": "MOBILE",
"identityValue": "917069914791",
"status": "PENDING",
"type": "PRIMARY"
}
],
"phoneDetail": {
"countryCode": "91",
"country": "IN",
"type": "MOBILE",
"location": "India",
"timeZones": [
"Asia/Calcutta"
]
},
"deviceFingerprinting": {
"status": "SUCCESS",
"sessionId": "a98ead44-f4db-4801-8c3f-041f98140734",
"deviceId": "781b21f7-220b-4f44-9155-6261f8564924",
"newDevice": false,
"riskAssessment": {
"sessionRiskLevel": "HIGH",
"deviceRiskLevel": "HIGH",
"sessionRiskScore": 95,
"deviceRiskScore": 90,
"ipFraudScore": 0,
"flags": {
"isVpn": false,
"isEmulator": false,
"isAppTampered": true
}
},
"deviceContext": {
"brand": "iQOO",
"model": "I2410",
"os": "Android",
"osVersion": "16"
},
"networkContext": {
"ipAddress": "106.205.222.198",
"ipType": "v4",
"asn": "45609",
"isp": "Bharti Airtel Limited"
}
}
}Status Check API
Poll the current auth status for a requestId. Returns the auth factor plus phone and device-fingerprinting detail when available.
curl --request GET \
--url https://auth.otpless.app/auth/v2/status \
--header 'clientId: <api-key>' \
--header 'clientSecret: <api-key>'import requests
url = "https://auth.otpless.app/auth/v2/status"
headers = {
"clientId": "<api-key>",
"clientSecret": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {clientId: '<api-key>', clientSecret: '<api-key>'}};
fetch('https://auth.otpless.app/auth/v2/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://auth.otpless.app/auth/v2/status",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"clientId: <api-key>",
"clientSecret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://auth.otpless.app/auth/v2/status"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("clientId", "<api-key>")
req.Header.Add("clientSecret", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://auth.otpless.app/auth/v2/status")
.header("clientId", "<api-key>")
.header("clientSecret", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://auth.otpless.app/auth/v2/status")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["clientId"] = '<api-key>'
request["clientSecret"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"auths": [
{
"identityType": "MOBILE",
"identityValue": "917069914791",
"status": "PENDING",
"type": "PRIMARY"
}
],
"phoneDetail": {
"countryCode": "91",
"country": "IN",
"type": "MOBILE",
"location": "India",
"timeZones": [
"Asia/Calcutta"
]
},
"deviceFingerprinting": {
"status": "SUCCESS",
"sessionId": "a98ead44-f4db-4801-8c3f-041f98140734",
"deviceId": "781b21f7-220b-4f44-9155-6261f8564924",
"newDevice": false,
"riskAssessment": {
"sessionRiskLevel": "HIGH",
"deviceRiskLevel": "HIGH",
"sessionRiskScore": 95,
"deviceRiskScore": 90,
"ipFraudScore": 0,
"flags": {
"isVpn": false,
"isEmulator": false,
"isAppTampered": true
}
},
"deviceContext": {
"brand": "iQOO",
"model": "I2410",
"os": "Android",
"osVersion": "16"
},
"networkContext": {
"ipAddress": "106.205.222.198",
"ipType": "v4",
"asn": "45609",
"isp": "Bharti Airtel Limited"
}
}
}requestId (ARID token) from the Create API to determine the final auth outcome. Poll until the PRIMARY factor reaches a terminal status (SUCCESS or FAILED).
clientId and clientSecret headers. Confirm a successful login based on this response — not on the SDK callback alone.deviceFingerprinting block is enriched only if the OTPless Device Intelligence SDK is imported and initialized in your client app. If it isn’t, the field is omitted from the response — the rest of the auth status is unaffected.Interpreting the result
Interpreting the result
PRIMARY factor’s status in auths[]:auths[].status | Meaning | Action |
|---|---|---|
PENDING | Authentication is still in progress. | Keep polling. |
SUCCESS | Authentication completed and the identity was verified. verifiedTimestamp is populated. | Log the user in and proceed with the journey. |
FAILED | Authentication could not be completed. An error object with errorCode and message is present. | Show a failure / retry flow. |
errorCode 7170 (“Auth not started yet”). This is not terminal — if auth has been initiated, keep polling. A 7119 (“Invalid request Id”) means the requestId is malformed.Poll until the PRIMARY factor reaches a terminal status (SUCCESS or FAILED), or until the request expires — the expiry you set in the Create API bounds the request’s validity.Verification error codes
Whenauths[].status is FAILED, inspect auths[].error.errorCode to determine the failure and your next step. See the full API Error Codes reference for the complete list of SP* codes and their messages.
Polling guidance
Begin polling after starting authentication on the client. Recommended strategy:| Parameter | Recommended value |
|---|---|
| Interval | 1 – 2 seconds |
| Terminal states | SUCCESS or FAILED — stop polling immediately. |
| Timeout | If still PENDING after your max attempts (bounded by expiry), treat as timeout and show a retry flow. |
errorCode 7170 is transient — it can appear briefly before auth initializes. Keep polling if auth was initiated; only 7119 indicates a malformed requestId.Authorizations
OTPless API Client ID
OTPless API Client Secret
Query Parameters
The ARID token (requestId) returned by POST /auth/v1/create.
"ARID_A1B2C3D4E5F6"
Response
HTTP 200 — Current auth status for the requestId. auths[].status is PENDING, SUCCESS, or FAILED.
Authentication factor(s) for the request. Read the PRIMARY factor for the final outcome.
Show child attributes
Show child attributes
Phone number metadata. Present when the identity is a phone number.
Show child attributes
Show child attributes
Device risk and context signals. Enriched only if the OTPless Device Intelligence SDK is imported and initialized in the client app; otherwise this field is omitted.
Show child attributes
Show child attributes