Skip to content

Verify a PIN

Request

Verifies a PIN challenge when calling a SCA-secured endpoint. Make sure to create a PIN before using this endpoint.

The request and response are encrypted using the JOSE framework. Please refer to the SCA over API guide to understand how encryption and decryption work.

Security
UserToken
Path
profileIdinteger, (int64)required

The profile ID.

Headers
One-Time-Tokenstring, (uuid)required

A one-time token unique identifier.

Acceptstringrequired
Default:"application/jose+json"
Accept-Encodingstringrequired
Default:"identity"
Content-Encodingstringrequired
Default:"identity"
X-tw-jose-methodstringrequired
Default:"jwe"
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
Bodyapplication/jose+jsonrequired
string

A JWE encrypted string. The decrypted payload contains:

  • pin — A four-digit string.

Payload before encryption:

{"pin": "1234"}
curl -X POST \
  'https://api.wise-sandbox.com/v2/profiles/{profileId}/pin/verify' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Accept: application/jose+json' \
  -H 'Accept-Encoding: identity' \
  -H 'Content-Type: application/jose+json' \
  -H 'Content-Encoding: identity' \
  -H 'X-tw-jose-method: jwe' \
  -H 'One-Time-Token: <one-time token>' \
  -d 'eyJlbmMiOiJBMjU2R0NNIiwiYWxnIjoiUlNBLU9BRVAtMjU2In0.W0fuxaZOoyaBcx...'

Responses

The PIN has been successfully verified.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Bodyapplication/json
oneTimeTokenstring, (uuid)

A one-time token unique identifier.

Example:"5932d5b5-ec13-452f-8688-308feade7834"
challengesArray of objects

An array of challenges.

validityinteger

The One-Time Token expiration in seconds.

Example:3600
Response
{ "oneTimeToken": "5932d5b5-ec13-452f-8688-308feade7834", "challenges": [ { "primaryChallenge": {}, "passed": false } ], "validity": 3600 }