Skip to main content
POST
Verify or link UPA email
By default this creates a single-use email OTP challenge, valid for ten minutes, for an unverified UPA. Complete it with Confirm an account email verification. If the app environment’s account email policy is partner_asserted, send verification.method: partner_asserted to link an email you already verified. Stableyard marks the email verified without sending its own OTP. Once verified, the UPA email cannot be changed through partner APIs: requesting the same email is an idempotent no-op, and a different email returns 409 conflict. Corrections need a privileged, audited operations workflow. Idempotency-Key is required; reuse it only with the identical email and assertion fields.

Authorizations

Authorization
string
header
required

HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.

Headers

Idempotency-Key
string
required

Use this for retry-safe payment operations from your backend.

Example:

"payment-request-001"

Stableyard-Version
enum<string>

Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.

Available options:
2026-09-09

Path Parameters

accountId
string
required

Canonical account id returned by the Accounts API.

Example:

"acct_123"

Body

application/json
email
string<email>
required
Maximum string length: 320
verification
object

Response

Email verification challenge

contact
object
required
nextAction
object
required
challenge
object