openapi: 3.2.0 info: version: '1.0' title: Auth Services OTP Auth API summary: List of services for customer authentication description: This API provides endpoints to perform customer authentication e.g. using OTP verification contact: name: akhilesh url: https://spliceforms.com/ email: api@apibanking.com license: url: https://spliceforms.com/ name: Commercial servers: - url: https://api.stitch.spliceforms.com/auth tags: - name: OTP Auth description: API endpoints for token issuance on successful OTP authentication paths: /v1/otp/initiate: post: summary: Initiate OTP Authentication Flow description: 'This endpoint initiates the user authentication flow using user identity information. It includes either the combination of mobile number and PAN or mobile number and date of birth. It sends an OTP to the mobile number provided by the user.' operationId: initiateAuthentication requestBody: content: application/json: schema: $ref: '#/components/schemas/OTPChallengeRequest' responses: '200': description: Returns the OTP challenge response content: application/json: schema: $ref: '#/components/schemas/OTPChallengeResponse' '400': description: This status code indicates that the server could not understand or process the request due to invalid syntax or parameters. The client should modify the request and retry. content: application/json: schema: $ref: '#/components/schemas/ProblemJson' '500': description: This status code means the server ran into an unexpected problem while processing your request. It indicates an issue on the server side, not with your input. Try refreshing or resubmitting your request after a short wait. content: application/json: schema: $ref: '#/components/schemas/ProblemJson' examples: Example 1: value: title: string status: 500 detail: string instance: http://example.com servers: - url: https://api.stitch.spliceforms.com/capture x-stoplight: id: 2ua89gmlwh9pu tags: - OTP Auth /v1/otp/resend: post: summary: Resend OTP description: This endpoint resends the OTP for ongoing authentication session. operationId: resendOTP requestBody: content: application/json: schema: $ref: '#/components/schemas/OTPResendRequest' responses: '200': description: Returns the OTP challenge response content: application/json: schema: $ref: '#/components/schemas/OTPChallengeResponse' '400': description: This status code indicates that the server could not understand or process the request due to invalid syntax or parameters. The client should modify the request and retry. content: application/json: schema: $ref: '#/components/schemas/ProblemJson' examples: Example 1: value: title: string status: 400 detail: string instance: http://example.com validationErrors: - message: string properties: - string severity: ERROR '500': description: This status code means the server ran into an unexpected problem while processing your request. It indicates an issue on the server side, not with your input. Try refreshing or resubmitting your request after a short wait. content: application/json: schema: $ref: '#/components/schemas/ProblemJson' examples: Example 1: value: title: string status: 500 detail: string instance: http://example.com servers: - url: https://api.stitch.spliceforms.com/capture x-stoplight: id: g1gz6gmxzhc3u tags: - OTP Auth /v1/otp/token: post: summary: Verify OTP and Issue Token description: This endpoint verifies the OTP and returns access and ID tokens post successful OTP verification operationId: verifyOTPAndIssueToken requestBody: content: application/json: schema: $ref: '#/components/schemas/OTPChallengeAnswer' responses: '200': description: Returns the access token & ID token on successful OTP verification content: application/json: schema: $ref: '#/components/schemas/OTPAuthResponse' '400': description: This status code indicates that the server could not understand or process the request due to invalid syntax or parameters. The client should modify the request and retry. content: application/json: schema: $ref: '#/components/schemas/ProblemJson' examples: Example 1: value: title: string status: 400 detail: string instance: http://example.com validationErrors: - message: string properties: - string severity: ERROR '500': description: This status code means the server ran into an unexpected problem while processing your request. It indicates an issue on the server side, not with your input. Try refreshing or resubmitting your request after a short wait. content: application/json: schema: $ref: '#/components/schemas/ProblemJson' examples: Example 1: value: title: string status: 500 detail: string instance: http://example.com servers: - url: https://api.stitch.spliceforms.com/capture x-stoplight: id: 2s3ghs8yax70m tags: - OTP Auth components: schemas: OTPChallengeRequest: type: object title: OTPChallengeRequest x-stoplight: id: r7ybne8md89ak required: - channelId - identity properties: channelId: x-unresolved-stoplight-ref: stoplight://resources/overrides/GirFFZFRFvU identity: oneOf: - $ref: '#/components/schemas/MobileAndDob' - $ref: '#/components/schemas/MobileAndPan' OTPAuthSession: type: string title: OTPAuthSession description: Encrypted string that contains OTP Auth session information pattern: ^.*$ minLength: 1 maxLength: 1000 examples: - dsf23rfvdf x-stoplight: id: hlir38dud4lqd OTPAuthResponse: type: object title: OTPAuthResponse x-stoplight: id: 8gfzq9ydu7h4h required: - accessToken properties: accessToken: $ref: '#/components/schemas/AccessToken' idToken: $ref: '#/components/schemas/IDToken' OTPChallengeResponse: type: object title: OTPChallengeResponse x-stoplight: id: flc3tvrlwt18y required: - expiresAt - session properties: expiresAt: description: The timestamp when the OTP will expire x-unresolved-stoplight-ref: stoplight://resources/overrides/fUrz7DdiN1w remainingAttempts: type: integer description: The number of attempts remaining for the user to enter OTP format: int32 minimum: 0 maximum: 5 examples: - 3 session: $ref: '#/components/schemas/OTPAuthSession' OTPChallengeAnswer: type: object title: OTPChallengeAnswer x-stoplight: id: o3ws0wqyuieha required: - session - otp properties: session: $ref: '#/components/schemas/OTPAuthSession' otp: x-unresolved-stoplight-ref: stoplight://resources/overrides/BjPbf7v8HHs MobileAndPan: type: object title: MobileAndPan x-stoplight: id: w09k4eguwygih required: - mobileNo - pan properties: mobileNo: x-unresolved-stoplight-ref: stoplight://resources/overrides/LT9qrA1aRC4 pan: x-unresolved-stoplight-ref: stoplight://resources/overrides/iQ8vF5vM3JE AccessToken: type: object title: AccessToken description: The access tokem x-stoplight: id: htg0m1yjnmnmt required: - token - expiresAt properties: token: x-unresolved-stoplight-ref: stoplight://resources/overrides/ZTFcuZFw8X0 expiresAt: x-unresolved-stoplight-ref: stoplight://resources/overrides/Dudc9ZZNUk4 ValidationError: type: object x-stoplight: id: i03w36ken44hv title: ValidationError description: Validation Error required: - message - severity properties: message: type: string description: Message for the validation error pattern: ^[A-Za-z0-9-_ ]+ minLength: 2 maxLength: 2048 examples: - fields can not be empty x-stoplight: id: vfc11e0vv4ka0 fields: type: array description: One or more properties on which the validation was performed. items: type: string description: Propertie on which the validation was performed. pattern: ^[A-Za-z0-9-_]+ minLength: 2 maxLength: 50 examples: - '23212322' x-stoplight: id: 7ezn2bw6cptug x-stoplight: id: ngstgikrr1jga severity: type: string enum: - ERROR - WARNING description: Severity of the validation error. pattern: ^[A-Z]+(_[A-Z]+)*$ minLength: 2 maxLength: 50 examples: - ERROR x-stoplight: id: kcvbyilxmlci5 OTPResendRequest: title: OTPResendRequest x-stoplight: id: sfzvrc1f6tv7q type: object description: 'Request for resending OTP ' required: - session properties: session: $ref: '#/components/schemas/OTPAuthSession' x-stoplight: id: fg52rp1kugcmt ProblemJson: type: object x-stoplight: id: oooamay5pgk0b title: ProblemJson description: Problem Error Json required: - title - status properties: title: type: string description: A short, human-readable summary of the problem type. It SHOULD NOT change from occurrence to occurrence of the problem, except for purposes of localization (e.g., using proactive content negotiation; see [RFC7231], Section 3.4). pattern: ^[A-Za-z0-9-_]+ minLength: 2 maxLength: 50 examples: - Unauthorized x-stoplight: id: qp048dxgamcyv status: type: integer description: The HTTP status code ([RFC7231], Section 6) generated by the origin server for this occurrence of the problem. format: int32 minimum: 1 maximum: 1000 examples: - 200 x-stoplight: id: mppplj2ikgpo5 detail: type: string description: A human-readable explanation specific to this occurrence of the problem. pattern: ^[A-Za-z0-9-_ ]+ minLength: 5 maxLength: 2043 examples: - api_key missing x-stoplight: id: 05ie4179zj1s5 instance: type: string description: A URI reference that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced. format: uri pattern: ^(https?|http):\/\/[^\s/$.?#].[^\s]*$ minLength: 5 maxLength: 2083 examples: - https://example.com/resource x-stoplight: id: f0d9smdiysl1b validationErrors: type: array description: Validation Errors items: x-stoplight: id: 7vcjnrvdy7wos $ref: '#/components/schemas/ValidationError' x-stoplight: id: uxclbrhmspafm MobileAndDob: type: object title: MobileAndDob x-stoplight: id: mupp5eht54exo required: - mobileNo - dob properties: mobileNo: x-unresolved-stoplight-ref: stoplight://resources/overrides/LT9qrA1aRC4 dob: x-unresolved-stoplight-ref: stoplight://resources/overrides/UEKAfGKnXtA IDToken: type: object title: IDToken description: The ID token x-stoplight: id: q19i5cca208yy required: - token - expiresAt properties: token: x-unresolved-stoplight-ref: stoplight://resources/overrides/ZTFcuZFw8X0 expiresAt: x-unresolved-stoplight-ref: stoplight://resources/overrides/Dudc9ZZNUk4 x-stoplight: id: znydl40fblitz x-source: https://github.com/spliceforms/stoplight-projects/blob/main/stitch-capture-services/auth-services-v1.0.yaml x-bundled-from: openapi/_original/stitch-capture-services/auth-services-v1.0.yaml (./models refs inlined into components/schemas; stoplight:// platform overrides are not resolvable outside Stoplight and are kept as x-unresolved-stoplight-ref)