Verifies a PIN challenge when calling a SCA-secured endpoint. Make sure to create a PIN before using this endpoint.
The request and response are encrypted using the JOSE framework. Please refer to the SCA over API guide to understand how encryption and decryption work.
Security
UserToken
Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.
Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
- Production Environmenthttps://api.wise.com/v2/profiles/{profileId}/pin/verify
- Sandbox Environmenthttps://api.wise-sandbox.com/v2/profiles/{profileId}/pin/verify
curl -X POST \
'https://api.wise-sandbox.com/v2/profiles/{profileId}/pin/verify' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'Accept: application/jose+json' \
-H 'Accept-Encoding: identity' \
-H 'Content-Type: application/jose+json' \
-H 'Content-Encoding: identity' \
-H 'X-tw-jose-method: jwe' \
-H 'One-Time-Token: <one-time token>' \
-d 'eyJlbmMiOiJBMjU2R0NNIiwiYWxnIjoiUlNBLU9BRVAtMjU2In0.W0fuxaZOoyaBcx...'The PIN has been successfully verified.
Headers
Echoed back when X-External-Correlation-Id was included in the request. Learn more.
Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
Response
{ "oneTimeToken": "5932d5b5-ec13-452f-8688-308feade7834", "challenges": [ { "primaryChallenge": { … }, "passed": false } ], "validity": 3600 }