Strong Customer Authentication
Complete an SCA login
Finalize an SCA login by submitting the proof for the started factor (code for SMS_OTP / TOTP, or passkeyAssertion + origin for PASSKEY), echoing the challengeId for SMS_OTP. Returns the reported session status.
This endpoint is only meaningful for customers in a region where SCA is required (e.g. EU). For customers outside SCA-regulated regions, this returns 409.
In sandbox, the SMS/TOTP code is always 123456.
post/sca/login/complete
Request body
Example request
{
"endUserIpAddress": "203.0.113.42",
"code": "123456",
"origin": "https://app.example.com"
}Response
SCA login completed; the session status is returned.
Example response
{
"status": "SUCCESS",
"sessionExpiresAt": "2026-01-29T12:00:00Z"
}