Before you start
How the code flow works
1
Your site requests a code
The customer enters their email address or mobile number on your site. Your site calls
POST /api/auth/email-code or POST /api/auth/sms.2
Omneo sends the code
When the profile exists, Omneo issues a 6-digit code and sends it using your configured email template or SMS sender. Nothing is sent for an unknown contact.
3
Your site verifies the code
The customer enters the code on your site. Your site calls
POST /api/auth/code/verify with the code and the same email address or mobile number.4
Omneo returns an ID token
Omneo checks the code, invalidates it, and returns a profile-scoped Omneo ID token. Use it to open Profile Portal already logged in, or call the Omneo ID service directly. See Use the token.
Send a magic link
Body
Other fields accepted by this endpoint are used by Profile Portal’s own pages and are not needed from an external site.
Responses
identity is the customer’s loyalty card number when your tenant has a loyalty card identity configured, otherwise false.
Send a login code by email
Body
Responses
Send a login code by SMS
Body
Responses
Verify a code
Body
Responses
POST /api/auth/sms/retrieve is a legacy alias of this endpoint with the same body and responses. Use /api/auth/code/verify for new integrations.
Use the token
Thetoken returned by verify is the same value Profile Portal puts in its own magic links, so you have two options.
Open Profile Portal logged in. Redirect the customer to the portal’s login route with the token and an optional path:
pid (profile ID) and exp (unix expiry) claims, and use the JWT as a bearer token against the Omneo ID service, for example GET https://api.[tenant].getomneo.com/id/api/v1/profiles/me. The steps are the same as validating the ID token on app open. The token is short-lived; to refresh it, mint a new one server-side as described in Using Omneo ID.
Code behaviour
Example
type: "existing", the second returns { "data": { "token": "<base64-jwt>", "id": "<profile-id>" } }, and repeating the second call returns 400 because the code has been used.