---
title: "Resend a quote's SCA challenge code"
method: POST
path: "/quotes/{quoteId}/authorize/resend"
tags: ["Strong Customer Authentication"]
---

# Resend a quote's SCA challenge code

`POST /quotes/{quoteId}/authorize/resend`

Re-send the one-time code for a realtime-funding quote in
`PENDING_AUTHORIZATION` status whose `scaChallenge.factor` is `SMS_OTP`. The
existing challenge is reused — no new challenge is issued, and its
`scaChallenge.expiresAt` is **not** extended; once the challenge is past
`expiresAt` it can no longer be authorized.

Only meaningful for customers in a region where SCA is required (e.g. EU);
a 409 is returned otherwise. `PASSKEY` challenges cannot be re-sent and return 409.

In sandbox, the code is always `123456`.

## Response `204`

Code re-sent.

## Other responses

- `401` — Unauthorized
- `404` — Quote not found
- `409` — SCA is not required for this customer, the quote has no pending SMS challenge, or the challenge uses a factor whose code cannot be re-sent (e.g. passkey).
- `429` — Too many requests. Returned with `RATE_LIMITED` when codes are re-sent too frequently, to avoid spamming the customer's phone. Clients should back off and retry after the interval indicated by the `Retry-After` response header.
- `500` — Internal service error

---

[API](https://skmtc.net/stainless-api/apis/grid-api.md) · [All operations](https://skmtc.net/stainless-api/apis/grid-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/stainless-api/grid-api/versions/151f2d9bad9c/schema)
