Send OTP
Emails a one-time password to the given address. Authentication is handled by **Better Auth**, mounted at `/api/v1/auth`. Its endpoints return Better Auth's own payloads — they are **not** wrapped in the `{ success, message, data }` envelope the rest of this API uses. Rate limited to 3 requests per minute per IP.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
curl -X POST "https://example.com/api/v1/auth/email-otp/send-verification-otp" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "type": "sign-in" }'{ "success": true}Authentication Module
Identity management and session control via Email OTP and secure cookies.
Sign In With Email OTPPOST
Exchanges a valid OTP for a session. On success the session cookie is set via `Set-Cookie` and the session token plus the user record are returned. A user is created automatically on first sign-in. Codes expire after 5 minutes and allow 3 attempts by default. This endpoint returns Better Auth's payload, not the `{ success, message, data }` envelope. Rate limited to 20 requests per minute per IP — the default for `/api/v1/auth/*`. (A tighter 5/minute rule exists in configuration but targets `/email-otp/verify-otp`, a path this Better Auth version does not expose, so it never applies.)