Introducing K-OTP
Phone verification is table stakes for almost every service in Korea, yet getting it right is fiddly: generate a code, send it over SMS or KakaoTalk AlimTalk, track expiry and attempts, and make sure a flaky network never delivers the same message twice. K-OTP reduces all of that to two endpoints.
Issue, then verify
Send the phone number, a purpose, and an idempotency key to POST /v1/issue. A 6-digit code is generated server-side and delivered over SMS or AlimTalk. If AlimTalk delivery fails, the code goes out by SMS automatically — still 1 credit. Send the returned issueId and the code your user typed to POST /v1/verify, and you are done. Codes expire after 3 minutes and allow 5 attempts by default.
Retries send once
Every issue requires an idempotency key. If a request times out, retry with the same key: the same key and payload return the first result without charging credits again. When a provider outcome is ambiguous, K-OTP does not resend automatically.
Designed to forget
Issue records keep only a hash of the phone number. Codes are stored as hashes and never returned by the API. Recipient fields in delivery records are encrypted and deleted about 24 hours after a final status.
Two kinds of keys
Use sk_ secret keys on your server and pk_ public keys in the browser. Public keys only work from Origins you register, and only for issue and verify.
Get started
Read the quickstart in the docs and the API reference. Pricing is prepaid credits — see the pricing page.