Docs
Firmly Agentic Commerce
Set theme to dark (⇧+D)

verifyOtp

​​ Overview

verifyOtp submits the OTP code the cardholder typed. On success, the FlowSession holds the new virtualCardId and the enrollment is complete.

If the wallet requires further verification, the result returns additional verificationMethods instead of a virtualCardId.

​​ Signature


const result = await fap.verifyOtp(session, code, options);

​​ Parameters

  • session (FlowSession, required) — The session from triggerOtp.

  • code (string, required) — The OTP code the cardholder entered.

  • options (object) — Optional CallOptions: apiTokenOverride, signal.

​​ Returns

Promise<VerifyOtpResult>

  • session (FlowSession) — The advanced session.

  • virtualCardId (string | null) — Set when verification completed enrollment. null when more verification is required.

  • verificationMethods (array | null) — Returned (instead of virtualCardId) when the wallet asks for additional verification. null otherwise.

​​ Example


// `session` here is the advanced session returned by triggerOtp.
const {
session: verifiedSession,
virtualCardId,
verificationMethods
} = await fap.verifyOtp(session, codeTheUserEntered);
if (virtualCardId) {
// Enrollment complete — continue to createIntent with verifiedSession.
} else if (verificationMethods) {
// The wallet asked for another verification step — carry verifiedSession forward.
}

​​ Errors

  • Wrong OTP code (400 BadRequest). An incorrect code is treated as a failure: the call rejects with a REST 400 BadRequest error surfaced through the SDK — the network (VTS) reports a wrong OTP as BadRequest, not a distinct InvalidOtp literal on this path. It does not resolve with a null virtualCardId. Catch it and prompt the cardholder to re-enter the code (you may call triggerOtp again to resend). A null virtualCardId on a resolved result means enrollment needs a further step (see verificationMethods), not a bad code.
  • 503 / timeout / abort. As with the other calls, an unavailable service, an exceeded timeoutMs, or an aborted options.signal reject the promise.