tencent cloud

ドキュメントTencent OneID Identity Security

SMS and Email OTP Authentication

ダウンロード
フォーカスモード
フォントサイズ
最終更新日: 2026-08-26 15:38:13
AI翻訳

API Description

Verify the SMS or email OTP verification code, obtain the Access Token and ID Token, and complete the login. Before calling this API, you must first send the verification code to the user via the Send OTP Verification Code interface.
Note:
You can enable automatic user registration by passing the auto_signup=true parameter.

Supported Application Types

Web applications, single-page applications, and mobile apps.

Request Method

POST

Request path

/oauth2/token

Request Content-Type

application/json

Request Example

SMS OTP Login

POST /oauth2/token HTTP/1.1
Content-Type: application/json
Host: sample.portal.tencentciam.com

{
"grant_type" : "http://tencentciam.com/oauth2/grant-type/otp/sms",
"client_id" : "TENANT_CLIENT_ID",
"client_secret" : "TENANT_CLIENT_SECRET",
"auth_source_id" : "MOCK_SMS_OTP_AUTH_SOURCE_ID",
"phone_number" : "13612345678",
"otp_token" : "MOCK_OTP_TOKEN",
"otp" : "123456"
}

Email OTP Login

POST /oauth2/token HTTP/1.1
Content-Type: application/json
Host: sample.portal.tencentciam.com

{
"grant_type" : "http://tencentciam.com/oauth2/grant-type/otp/email",
"client_id" : "TENANT_CLIENT_ID",
"client_secret" : "TENANT_CLIENT_SECRET",
"auth_source_id" : "MOCK_EMAIL_OTP_AUTH_SOURCE_ID",
"email" : "MOCK_USERNAME@example.com",
"otp_token" : "MOCK_EMAIL_OTP_TOKEN",
"otp" : "123456"
}

Request Body JSON Parameters

JSON Path
Data Type
Description
grant_type
String
SMS OTP login endpoint: http://tencentciam.com/oauth2/grant-type/otp/sms
Email OTP login endpoint: http://tencentciam.com/oauth2/grant-type/otp/email
client_id
String
The application's client_id. It must match the one used when the verification code is sent.
client_secret
String
The application's client_secret. Web applications must pass this parameter. Single-page applications and mobile apps do not pass this parameter.
auth_source_id
String
The SMS OTP or email OTP authentication source ID. It must match the one used when the verification code is sent.
phone_number
String
The user's mobile phone number. It must match the one used when the verification code is sent. Pass this parameter during SMS OTP login.
email
String
The user's email address. It must match the one used when the verification code is sent. Pass this parameter during email OTP login.
otp_token
String
The otp_token returned by the server after the verification code is sent successfully.
otp
String
The OTP verification code received by the user's mobile phone or email.
auto_signup
Boolean
Set this parameter to true if you need to support automatic user registration. Otherwise, you can omit it.

Normal Response Example

HTTP/1.1 200 OK
Content-Type: application/json;charset=UTF-8

{
"access_token" : "eyJraWQiOiJmZTQ4YTJjYS1lNGU3LTQyMGEtOThjOS01OGM5NmI2NzUwZjIiLCJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJNT0NLX1VTRVJfSUQiLCJhdWQiOiJURU5BTlRfQ0xJRU5UX0lEIiwibmJmIjoxNjQ3NDIwMDM1LCJzY29wZSI6WyJvcGVuaWQiXSwiaXNzIjoiaHR0cHM6XC9cL3NhbXBsZS5wb3J0YWwudGVuY2VudGNpYW0uY29tIiwiZXhwIjoxNjQ3NDIwMzM1LCJpYXQiOjE2NDc0MjAwMzUsImp0aSI6ImMxZmE5Yzk4LThhZjQtNDA1Zi1iOWFhLTdiNTU2MjY1NDljNSJ9.FzvKdLeIgNeYKwQeixIGKX2JPkZ9tJ43fnwuaruLY85RQj9cMedm9eSU4Ft_h7NJkwH-eBTmSybg7174RsQ98yOaW77u2flQwxm0xZCx74kY2dOZOf3YhRJwVLVhocMtLC1NrrP3phJSVfYYzClS_ppTnSHcGZhiVzW57YgolTr0EeuOMucmt1jh_I76kDreo_B5UhV95sRqP_R5FMVBLpGvlAD3TPVCMs3zQETlgHHyq2UE9YBnkNBLK9RzxknRZ0XSnUMxpcPCod4e7Q7S87QqML2S_3AbcmJlPY5q0D-XTqzyjvS2QByUOUQNOX6pEH4Pe7fV6phVrfXh0IenDQ",
"refresh_token" : "B-72VlkQa3jQNuo9Xbbl-muoh4w7nYu-7Q3Wb-qmPgyftN1CgXPov2aWsOBWeeIOIVHjVxxHxbOa21Oz0CtIgsIz1LMZ_HG7eLxF-qk6hiRcFzPOcSl8PBsCdd3QXaEd",
"scope" : "openid",
"id_token" : "eyJraWQiOiJmZTQ4YTJjYS1lNGU3LTQyMGEtOThjOS01OGM5NmI2NzUwZjIiLCJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJNT0NLX1VTRVJfSUQiLCJhdWQiOiJURU5BTlRfQ0xJRU5UX0lEIiwiYXpwIjoiVEVOQU5UX0NMSUVOVF9JRCIsImlzcyI6Imh0dHBzOlwvXC9zYW1wbGUucG9ydGFsLnRlbmNlbnRjaWFtLmNvbSIsImV4cCI6MTY0NzQyMTgzNSwiaWF0IjoxNjQ3NDIwMDM1LCJqdGkiOiI5MGFiMzljMi00NjQzLTQwYTEtODdmOC0yN2Q5ODkzOTExMDQifQ.ZqgRcJae_XEUd1XIbu2_pzdgnJCtEehLoCTTHJhEvewOeEnUlfYkRMrpfZ_hYSVsaWDZy0zdqntWmpmN57eJuw-nfwaUGBUjc1e3KgyvY9jr5vo4zlI5O2NJYYMwP8uwwCFsqWjbNl1cl-dVPu6pIGAvPWBx_Hm1C0vMsPICv61KE7I4bGi_XCSQ--CQjvjzE8ly4I7Z1jCfVl9f4Aybve2HJkuD-m73nZsgluAGOANXvBLcYi1bj4ncXt9Ybk45Gt_vtlCOY9Ab-N6STm4omtKuxyMQUfy7Rv-9RXBuvDFIdDl6tpENxch1N0V027FdtdWk_JOk9mq97rqI-LycPA",
"token_type" : "Bearer",
"expires_in" : 299
}

Response Parameters

Field
Data Type
Description
access_token
String
OAuth 2.0 Access Token (JWT).
token_type
String
The Token type. Currently, the fixed value 'Bearer' is returned.
expires_in
Number
The validity period of the Access Token, in seconds.
scope
String
Access Token scope.
refresh_token
String
OAuth 2.0 Refresh Token.
id_token
String
OIDC ID Token (JWT).

Exception Response Example

The otp_token is incorrect or has expired.
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_grant",
"error_description" : "Unknown or expired otp_token"
}
The otp is incorrect or has expired.
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_grant",
"error_description" : "Unknown or expired OTP"
}
The parameters used do not match those used when the verification code is sent (for example, the mobile phone number is different).
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_request",
"error_description" : "Mismatched OTP token and OTP sending parameters"
}
No user corresponding to the mobile phone number or email address is found (when automatic user registration is not allowed).
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_grant",
"error_description" : "User not found"
}
The status of the user corresponding to the mobile phone number or email address is abnormal (for example, the account is locked or frozen).
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_grant",
"error_description" : "Abnormal user status"
}
The authentication source is not the application's primary or associated authentication source.
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_auth_source",
"error_description" : "Auth source and application not associated"
}


ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック