---
title: "Authenticate by verifying the possession of a one-time token."
method: POST
path: "/verify"
tags: ["auth"]
---

# Authenticate by verifying the possession of a one-time token.

`POST /verify`

## Request body

- object
  - `type` 'signup' | 'recovery' | 'invite' | 'magiclink' | 'email_change' | 'sms' | 'phone_change'
  - `token` string
  - `token_hash` string — The hashed value of token. Applicable only if used with `type` and nothing else.
  - `email` string, email — Applicable only if `type` is with regards to an email address.
  - `phone` string, phone — Applicable only if `type` is with regards to an phone number.
  - `redirect_to` string, uri — (Optional) URL to redirect back into the app on after verification completes successfully. If not specified will use the "Site URL" configuration option. If not allowed per the allow list it will use the "Site URL" configuration option.

## Response `200`

An access and refresh token.

- AccessTokenResponseSchema
  - `access_token` string — A valid JWT that will expire in `expires_in` seconds.
  - `refresh_token` string — An opaque string that can be used once to obtain a new access and refresh token.
  - `token_type` string — What type of token this is. Only `bearer` returned, may change in the future.
  - `expires_in` integer — Number of seconds after which the `access_token` should be renewed by using the refresh token with the `refresh_token` grant type.
  - `expires_at` integer — UNIX timestamp after which the `access_token` should be renewed by using the refresh token with the `refresh_token` grant type.
  - `weak_password` object — Only returned on the `/token?grant_type=password` endpoint. When present, it indicates that the password used is weak. Inspect the `reasons` and/or `message` properties to identify why.
    - `reasons` string[]
    - `message` string
  - `user` UserSchema — Object describing the user related to the issued access and refresh tokens.
    - `id` string, uuid
    - `aud` string
    - `role` string
    - `email` string — User's primary contact email. In most cases you can uniquely identify a user by their email address, but not in all cases.
    - `email_confirmed_at` string, date-time
    - `phone` string, phone — User's primary contact phone number. In most cases you can uniquely identify a user by their phone number, but not in all cases.
    - `phone_confirmed_at` string, date-time
    - `confirmation_sent_at` string, date-time
    - `confirmed_at` string, date-time
    - `recovery_sent_at` string, date-time
    - `new_email` string, email
    - `email_change_sent_at` string, date-time
    - `new_phone` string, phone
    - `phone_change_sent_at` string, date-time
    - `reauthentication_sent_at` string, date-time
    - `last_sign_in_at` string, date-time
    - `app_metadata` object
    - `user_metadata` object
    - `factors` MFAFactorSchema[]
      - `id` string, uuid
      - `status` string — Usually one of: - verified - unverified
      - `friendly_name` string
      - `factor_type` string — Usually one of: - totp - phone - webauthn
      - `webauthn_credential` string
      - `phone` string, phone, nullable
      - `created_at` string, date-time
      - `updated_at` string, date-time
      - `last_challenged_at` string, date-time, nullable
    - `identities` IdentitySchema[]
      - `identity_id` string, uuid
      - `id` string, uuid
      - `user_id` string, uuid
      - `identity_data` object
      - `provider` string
      - `last_sign_in_at` string, date-time
      - `created_at` string, date-time
      - `updated_at` string, date-time
      - `email` string, email
    - `banned_until` string, date-time
    - `created_at` string, date-time
    - `updated_at` string, date-time
    - `deleted_at` string, date-time
    - `is_anonymous` boolean

## Other responses

- `429` — HTTP Too Many Requests response, when a rate limiter has been breached.

---

[API](https://skmtc.net/supabase/apis/supabase-auth-rest-api.md) · [All operations](https://skmtc.net/supabase/apis/supabase-auth-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/supabase/supabase-auth-rest-api/versions/2664b89bee49/schema)
