v5

OpenAPI 3.1.0Proprietary2026-08-011476181.4 MB
Strong Customer Authentication

Complete an SCA login

Finalize an SCA login by submitting the proof for the started factor (code for SMS_OTP / TOTP, or passkeyAssertion + origin for PASSKEY), echoing the challengeId for SMS_OTP. Returns the reported session status.

This endpoint is only meaningful for customers in a region where SCA is required (e.g. EU). For customers outside SCA-regulated regions, this returns 409.

In sandbox, the SMS/TOTP code is always 123456.

post/sca/login/complete

Request body

OR

Example request

{
  "endUserIpAddress": "203.0.113.42",
  "code": "123456",
  "origin": "https://app.example.com"
}

Response

SCA login completed; the session status is returned.

statusstring required

The status of the login session. A successful login reports SUCCESS; other values indicate the login did not complete and should be surfaced to the caller.

sessionExpiresAtstring date-time nullable

Absolute UTC timestamp after which the customer's SCA session is no longer valid and they must complete another SCA login. Money movement in SCA-regulated currencies is refused once it passes, so prompt a re-login ahead of it rather than waiting for a SCA_SESSION_REQUIRED failure. Present when the login established a session.

Example response

{
  "status": "SUCCESS",
  "sessionExpiresAt": "2026-01-29T12:00:00Z"
}