Sign In With Email OTP
Exchanges a valid OTP for a session. On success the session cookie is set via `Set-Cookie` and the session token plus the user record are returned. A user is created automatically on first sign-in. Codes expire after 5 minutes and allow 3 attempts by default. This endpoint returns Better Auth's payload, not the `{ success, message, data }` envelope. Rate limited to 20 requests per minute per IP — the default for `/api/v1/auth/*`. (A tighter 5/minute rule exists in configuration but targets `/email-otp/verify-otp`, a path this Better Auth version does not expose, so it never applies.)
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
curl -X POST "https://example.com/api/v1/auth/sign-in/email-otp" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "otp": "123456" }'{ "token": "string", "user": {}}Send OTPPOST
Emails a one-time password to the given address. Authentication is handled by **Better Auth**, mounted at `/api/v1/auth`. Its endpoints return Better Auth's own payloads — they are **not** wrapped in the `{ success, message, data }` envelope the rest of this API uses. Rate limited to 3 requests per minute per IP.
Get Current SessionGET
Returns the active session and its user, based on the request's session cookie. Returns `null` rather than an error when no valid session cookie is present. This endpoint returns Better Auth's payload, not the `{ success, message, data }` envelope.