Verify a code and open (or resume) the visitor's document
The only place a document is ever created from a public link. A visitor who verified before and abandoned it gets the same unfinished document back rather than a duplicate. Unauthenticated.
View as MarkdownPath Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/public/links/string/verify" \ -H "Content-Type: application/json" \ -d '{ "challengeId": "string", "code": "string" }'{ "documentId": "string", "signingUrl": "string"}Start email verification for a visitor
Never creates a document — issues (or reissues) a one-time code to the given email. Rate-limited on two independent dimensions: by IP (the whole public-links surface) and by the normalized email address itself, so a distributed attack aimed at one target inbox isn't just an IP problem. One-submission-per-email (when the link has it on) is never checked here — only after the code is verified, so this endpoint can't be used as an email-enumeration oracle. Unauthenticated.
All of the caller's public signing links
EAS-117. The "Public Signing" page's list — every one of the caller's links, owner-scoped. Unlike the old template-joined design, this is a plain read of the links' own rows — no join through Template.