Setup
How it works
- User submits their email to
POST /auth/email-otp/send. - KavachOS generates a cryptographically random code and calls your
onSendOtpfunction with the email and code. - User enters the code in your UI and submits to
POST /auth/email-otp/verify. - On success, a session cookie is set.
Send a code
POST /auth/email-otp/send
200 to prevent email enumeration. Codes are rate-limited to one per minute per email address, requests within the window return 429. Build a countdown timer into your UI.
Verify a code
POST /auth/email-otp/verify
maxAttempts failed verifications, the code is invalidated and a new one must be requested.