DigetPay Developer Integration API
  1. Login
  • Overview & Getting Started
  • Integration Flow
    • 01 - Authentication & Team
    • 02 - End-to-End Integration Flow
    • 03 - Customizing your Marketplace Listing
  • API Reference
    • Auth
      • Refresh access token using a refresh token
      • Logout — revoke the refresh token
      • Get current profile
      • Activate an invited `DEVELOPER` account (set password from invite link)
    • Login
      • Login with email + password (sends OTP via email and SMS)
        POST
      • Verify the login OTP and issue access + refresh tokens
        POST
      • Resend login OTP via email and SMS
        POST
    • Register
      • Self-register a developer company + owner account
      • Verify registration OTP (email + phone)
      • Resend registration OTP
    • Forgot Password
      • Forgot password — send a reset OTP to the email
      • Verify the forgot-password OTP
      • Reset the password using the reset token
    • Team
      • List organization members
      • Invite a `DEVELOPER` into the organization
      • Resend the activation link for a `PENDING` member
      • Remove a member
    • Company
      • Change Requests
        • Submit a company information change request
        • Withdraw a pending change request
        • Upload a document for a company change request
        • Remove a staged document from a change request
        • Get current pending company change request
      • Company profile + verification status + documents
      • Respond to a single information request
      • Update company / verification data (DRAFT or INFO_REQUIRED only)
      • Onboarding readiness for verification submit and marketplace
      • Upload a verification document (pdf/jpeg/png, max 10MB)
      • Signed download URL for an own document
      • Submit company for verification review
      • Verification status only
      • List information requests for the current verification
    • Applications
      • List applications
      • Create application (requires APPROVED verification)
      • Active marketplace categories (for the listing form)
      • Application detail
      • Update application
      • Request production activation (certification must be PASSED)
      • Upload an application logo (icon)
      • Upload an application banner
      • Marketplace orders for the application
      • API request logs (masked metadata only)
      • Orders / transactions for the application
      • Advance a confirmation-required order
      • Submit application for review
    • Listings
      • Marketplace listing for the application
      • Create or partially update the marketplace listing
      • Submit listing for marketplace review
      • Unpublish a live or scheduled marketplace listing
    • Offers
      • List authored marketplace offers (cards)
      • Create a marketplace offer (card)
      • Reorder marketplace offers
      • Update a marketplace offer (card)
      • Delete a marketplace offer (card)
      • Upload a marketplace offer (card) image
      • Upload an offer (card) banner image
    • Panels
      • Upload a panel (section) banner image
      • List marketplace panels (sections)
      • Create a marketplace panel (section)
      • Reorder marketplace panels (sections)
      • Update a marketplace panel (section)
      • Delete a marketplace panel (section)
    • Credentials
      • List credentials (masked)
      • Generate credential for an environment — raw key returned once
      • Rotate API key — new raw key returned once
      • Rotate webhook signing secret — returned once
      • Revoke credential (`isActive=false`)
      • Set optional IP allowlist (IPv4 / CIDR)
    • Webhooks
      • Webhook event catalog
      • List webhook endpoints
      • Add webhook endpoint (**max 5 per environment**)
      • Update webhook endpoint
      • Delete webhook endpoint
      • Send a signed connection test to the endpoint
      • Delivery logs
    • Dashboard
      • Developer portal overview
    • Company
  • Developer Portal
    • Applications
    • Certification
      • Certification progress ("8 of 12 tests completed")
      • Re-evaluate automated certification checks
    • Auth
      • Login
        • Login with email + password (no OTP — non-production only)
  • admin
    • auth
      • Step 1: email + password → email OTP
      • Step 2: verify OTP → admin JWT
      • Resend OTP (re-runs login challenge)
      • Get current admin user profile
      • Update current admin profile (name, phone, avatar)
      • Change password for the current admin user
      • Logout admin user
      • Set password from an invite link token (no auth required)
      • Request password reset via email/SMS OTP (no auth required)
      • Verify password reset OTP and get reset token (no auth required)
      • Reset password using reset token and new password (no auth required)
  • integrity
    • Issue a one-time nonce for Play Integrity attestation
    • (DEV ONLY) Decode an integrity token and return the verdict
  • health
    • Liveness probe - basic health check
    • Readiness probe - dependency health check
    • HealthController_getMetrics
  • super-admin-portal
    • impersonate
      • Impersonate a partner or merchant OWNER by targetId + targetType
      • End an active impersonation session
  1. Login

Verify the login OTP and issue access + refresh tokens

Staging
https://fin-api.digetpay.com
Staging
https://fin-api.digetpay.com
POST
https://fin-api.digetpay.com
/v1/developer-portal/auth/login/verify-otp
Exchanges the OTP challenge for an access token (12h) and a refresh token
(30 days). The challenge is single-use and deleted on success.
Send the access token as Authorization: Bearer <accessToken> for all
developer-portal endpoints. Rotate it via refresh before expiry.

Request

Body Params application/jsonRequired

Example
{
    "challengeId": "a1b2c3d4e5f60718293a4b5c",
    "otp": "123456"
}

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location 'https://fin-api.digetpay.com/v1/developer-portal/auth/login/verify-otp' \
--header 'Content-Type: application/json' \
--data '{
    "challengeId": "a1b2c3d4e5f60718293a4b5c",
    "otp": "123456"
}'

Responses

🟢200OK
application/json
OTP verified; tokens and identity returned.
Bodyapplication/json

Example
{
    "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMCJ9.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c",
    "refreshToken": "4f6b2a1c8e9d0f1a2b3c4d5e6f708192",
    "tokenType": "Bearer",
    "expiresIn": 43200,
    "user": {
        "id": "10",
        "email": "dev@company.com",
        "name": "Sarah Developer"
    },
    "organization": {
        "id": "42",
        "name": "Acme Payment Solutions",
        "legalName": "Acme Payment Solutions LLC",
        "status": "ONBOARDING"
    }
}
🟠400Bad Request
🟠401Unauthorized
Modified at 2026-09-16 09:43:02
Previous
Login with email + password (sends OTP via email and SMS)
Next
Resend login OTP via email and SMS
Built with