Confirm UPA email verification
curl --request POST \
--url https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"code": "123456"
}
'import requests
url = "https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm"
payload = { "code": "123456" }
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({code: '123456'})
};
fetch('https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'code' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm"
payload := strings.NewReader("{\n \"code\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"code\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"code\": \"123456\"\n}"
response = http.request(request)
puts response.read_body{
"contact": {
"id": "account_contact_123",
"type": "email",
"email": "al***@example.com",
"status": "verified",
"verifiedAt": "2026-08-28T10:02:00.000Z",
"verificationMethod": "stableyard_email_otp",
"createdAt": "2026-08-28T10:00:00.000Z",
"updatedAt": "2026-08-28T10:02:00.000Z"
},
"challenge": {
"id": "account_email_123",
"email": "al***@example.com",
"status": "verified",
"verificationMethod": "stableyard_email_otp",
"attemptsRemaining": 4,
"expiresAt": "2026-08-28T10:10:00.000Z",
"verifiedAt": "2026-08-28T10:02:00.000Z"
},
"nextAction": {
"type": "start_kyc_session"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid"
}
}{
"error": {
"code": "unauthorized",
"message": "Authentication is required"
}
}{
"error": {
"code": "forbidden",
"message": "The credential does not allow this operation"
}
}{
"error": {
"code": "not_found",
"message": "The resource was not found"
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The Idempotency-Key was already used with a different request"
}
}{
"error": {
"code": "chain_config_missing",
"message": "The requested network is not configured for this environment"
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests"
}
}Email verification
Confirm an account email verification
Submit the six-digit email code to mark a UPA’s email verified.
POST
/
v2
/
accounts
/
{accountId}
/
email
/
verification-challenges
/
{challengeId}
/
confirm
Confirm UPA email verification
curl --request POST \
--url https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"code": "123456"
}
'import requests
url = "https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm"
payload = { "code": "123456" }
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({code: '123456'})
};
fetch('https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'code' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm"
payload := strings.NewReader("{\n \"code\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"code\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://prod-api.stableyard.fi/v2/accounts/{accountId}/email/verification-challenges/{challengeId}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"code\": \"123456\"\n}"
response = http.request(request)
puts response.read_body{
"contact": {
"id": "account_contact_123",
"type": "email",
"email": "al***@example.com",
"status": "verified",
"verifiedAt": "2026-08-28T10:02:00.000Z",
"verificationMethod": "stableyard_email_otp",
"createdAt": "2026-08-28T10:00:00.000Z",
"updatedAt": "2026-08-28T10:02:00.000Z"
},
"challenge": {
"id": "account_email_123",
"email": "al***@example.com",
"status": "verified",
"verificationMethod": "stableyard_email_otp",
"attemptsRemaining": 4,
"expiresAt": "2026-08-28T10:10:00.000Z",
"verifiedAt": "2026-08-28T10:02:00.000Z"
},
"nextAction": {
"type": "start_kyc_session"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid"
}
}{
"error": {
"code": "unauthorized",
"message": "Authentication is required"
}
}{
"error": {
"code": "forbidden",
"message": "The credential does not allow this operation"
}
}{
"error": {
"code": "not_found",
"message": "The resource was not found"
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The Idempotency-Key was already used with a different request"
}
}{
"error": {
"code": "chain_config_missing",
"message": "The requested network is not configured for this environment"
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests"
}
}Consumes the six-digit OTP and atomically marks the UPA’s email verified. A failed challenge cannot be reused. Once the email is verified, the UPA can start KYC and use entitled fiat payment rails.
Authorizations
HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.
Headers
Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.
Available options:
2026-09-09 Path Parameters
Canonical account id returned by the Accounts API.
Example:
"acct_123"
Pattern:
^account_email_[A-Za-z0-9_-]+$Body
application/json
Pattern:
^[0-9]{6}$Example:
"123456"