Start email verification for a visitor
Never creates a document — issues (or reissues) a one-time code to the given email. Rate-limited on two independent dimensions: by IP (the whole public-links surface) and by the normalized email address itself, so a distributed attack aimed at one target inbox isn't just an IP problem. One-submission-per-email (when the link has it on) is never checked here — only after the code is verified, so this endpoint can't be used as an email-enumeration oracle. Unauthenticated.
View as MarkdownPath Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/public/links/string/start" \ -H "Content-Type: application/json" \ -d '{ "name": "string", "email": "string" }'{ "challengeId": "string"}Check a public link's availability
Never creates anything. One generic 404 for every pre-verification failure — bad token, paused, expired, or never existed — so there is no oracle for probing which case it is. Unauthenticated, IP rate-limited.
Verify a code and open (or resume) the visitor's document
The only place a document is ever created from a public link. A visitor who verified before and abandoned it gets the same unfinished document back rather than a duplicate. Unauthenticated.