Skip to main content
GET
Status Check
The Status Check API is the authoritative source of truth for the authentication flow. Your backend polls it with the requestId (ARID token) from the Create API to determine the final auth outcome. Poll until the PRIMARY factor reaches a terminal status (SUCCESS or FAILED).
This is a server-to-server call. It requires your clientId and clientSecret headers. Confirm a successful login based on this response — not on the SDK callback alone.
The deviceFingerprinting block is enriched only if the OTPless Device Intelligence SDK is imported and initialized in your client app. If it isn’t, the field is omitted from the response — the rest of the auth status is unaffected.
Read the PRIMARY factor’s status in auths[]:Before auth is initialized you may receive an HTTP 400 with errorCode 7170 (“Auth not started yet”). This is not terminal — if auth has been initiated, keep polling. A 7119 (“Invalid request Id”) means the requestId is malformed.Poll until the PRIMARY factor reaches a terminal status (SUCCESS or FAILED), or until the request expires — the expiry you set in the Create API bounds the request’s validity.

Verification error codes

When auths[].status is FAILED, inspect auths[].error.errorCode to determine the failure and your next step. See the full API Error Codes reference for the complete list of SP* codes and their messages.

Polling guidance

Begin polling after starting authentication on the client. Recommended strategy:
An HTTP 400 with errorCode 7170 is transient — it can appear briefly before auth initializes. Keep polling if auth was initiated; only 7119 indicates a malformed requestId.

Authorizations

clientId
string
header
required

OTPless API Client ID

clientSecret
string
header
required

OTPless API Client Secret

Query Parameters

requestId
string
required

The ARID token (requestId) returned by POST /auth/v1/create.

Example:

"ARID_A1B2C3D4E5F6"

Response

HTTP 200 — Current auth status for the requestId. auths[].status is PENDING, SUCCESS, or FAILED.

auths
object[]

Authentication factor(s) for the request. Read the PRIMARY factor for the final outcome.

phoneDetail
object

Phone number metadata. Present when the identity is a phone number.

deviceFingerprinting
object

Device risk and context signals. Enriched only if the OTPless Device Intelligence SDK is imported and initialized in the client app; otherwise this field is omitted.