POSTVerify Customer OTP
Verify the customer OTP to complete onboarding and return the customer profile.
Validates the OTP issued by Onboard Customer / Get Customer Information. For an existing customer the response returns the full customer_profile (limits, balance, KYC state). For a new customer the flow continues to Aadhaar validation and PAN.
Path parameters
| Field | Type | Required | Description |
|---|---|---|---|
customer_id | string | required | Customer's 10-digit mobile number.e.g. 9444444444 |
customer_idstringRequiredCustomer's 10-digit mobile number.
example: 9444444444
Body parameters
| Field | Type | Required | Description |
|---|---|---|---|
initiator_id | string | required | Registered mobile number of the API user (see Platform Credentials).e.g. 9962981729 |
user_code | string | required | User code of the retailer/agent the service is run for.e.g. 20810200 |
client_ref_id | string | optional | Unique reference id per API call, generated by your system.e.g. REQ-20260101-001 |
otp | integer | optional | OTP received from Onboard Customer, Get Customer Information, or Validate Aadhaar.e.g. 123456 |
otp_ref_id | integer | required | otp_ref_id received from Onboard Customer, Get Customer Information, or Validate Aadhaar.e.g. 66748392 |
initiator_idstringRequiredRegistered mobile number of the API user (see Platform Credentials).
example: 9962981729
user_codestringRequiredUser code of the retailer/agent the service is run for.
example: 20810200
client_ref_idstringoptionalUnique reference id per API call, generated by your system.
example: REQ-20260101-001
otpintegeroptionalOTP received from Onboard Customer, Get Customer Information, or Validate Aadhaar.
example: 123456
otp_ref_idintegerRequiredotp_ref_id received from Onboard Customer, Get Customer Information, or Validate Aadhaar.
example: 66748392
Headers
| Field | Type | Required | Description |
|---|---|---|---|
developer_key | string | required | Static API key issued to your account after KYC. |
secret-key | string | required | Dynamic per-request signature: base64(HMAC-SHA256(timestamp, base64(access_key))). |
secret-key-timestamp | string | required | Current time in milliseconds since UNIX epoch, used to compute secret-key. Must match server time. |
content-type | string | required | application/jsone.g. application/json |
developer_keystringRequiredStatic API key issued to your account after KYC.
secret-keystringRequiredDynamic per-request signature: base64(HMAC-SHA256(timestamp, base64(access_key))).
secret-key-timestampstringRequiredCurrent time in milliseconds since UNIX epoch, used to compute secret-key. Must match server time.
content-typestringRequiredapplication/json
example: application/json
Responses
statusnumberPrimary success indicator (0 = success).
messagestringHuman-readable response / error message.
response_status_idnumberGranular status id; see the shared error-codes table.
response_type_idnumberA unique id for every possible response shape (success or error) — useful for client logic branching and analytics.
dataobjectAPI-specific response payload.
customer_profileobjectCustomer's profile — limits, balance, KYC state, and usage chart.
namestringRegistered name of the customer.
mobilestringCustomer's mobile number.
next_allowed_limitstringRemaining transfer limit for the period (INR).
balancestringCurrent balance (INR).
kyc_statenumberKYC completion state.
sender_namestringRegistered name of the customer.