POST /api/auth/magic/code - the code shown on the other device, typed into the waiting window here. Completes the sign-in on THIS browser (the one that asked).
const url = 'https://example.com/api/auth/magic/code';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"code":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/auth/magic/code \ --header 'Content-Type: application/json' \ --data '{ "code": "example" }'Request Bodyrequired
Section titled “Request Bodyrequired”object
Examplegenerated
{ "code": "example"}Responses
Section titled “Responses”Session issued on the requesting device (or a 2FA interim)
object
object
Examplegenerated
{ "csrf_token": "example", "expires_in": 1, "user": { "email": "example", "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0" }}No session: the code was wrong or the request was refused
A code that did not sign this device in: wrong_code (with the attempts left)
or refused (with the kernel’s reason slug). 202, never 4xx: the request was
understood, the sign-in simply did not happen.
object
The server’s English wording; the client localises by outcome/reason.
wrong_code | refused
wrong_device | no_code_issued | code_expired | too_many_attempts |
already_completed | already_opened | invalidated | link_expired
Examplegenerated
{ "message": "example", "outcome": "example", "reason": "example", "remaining_attempts": 1}Structured client error
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}Structured server error
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}