Skip to main content
POST
Confirm UPA email verification
Consumes the six-digit OTP and atomically marks the UPA’s email verified. A failed challenge cannot be reused. Once the email is verified, the UPA can start KYC and use entitled fiat payment rails.

Authorizations

Authorization
string
header
required

HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.

Headers

Stableyard-Version
enum<string>

Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.

Available options:
2026-09-09

Path Parameters

accountId
string
required

Canonical account id returned by the Accounts API.

Example:

"acct_123"

challengeId
string
required
Pattern: ^account_email_[A-Za-z0-9_-]+$

Body

application/json
code
string
required
Pattern: ^[0-9]{6}$
Example:

"123456"

Response

Verified UPA email

contact
object
required
nextAction
object
required
challenge
object