Send an OTP
Send a one-time code to a phone or email, with no patient lookup attached.
POST /v1/otp/sendThe plain half of the OTP gate. Same delivery rail as send-phone-verification-otp, same rate limits — the difference is at the verify step, where this pair returns only the verification result and the patient pair also returns the patient's records.
Use this one when you already know who the patient is and only need the gate open.
Body
| Field | Type | Required | Description |
|---|---|---|---|
phoneNumber | string | Yes* | The number, without the dial code. |
countryCode | string | No | Dial code with the +. Defaults to +91. |
channel | string | No | whatsapp (default) or email. |
email | string | Yes* | *Instead of phoneNumber when channel is email. |
Try it
/v1/otp/sendOpens the 30-minute verified window for this x-end-user-id. Delivered over WhatsApp.
Body
POST /v1/otp/send{
"countryCode": "+91",
"phoneNumber": "9811100001"
}https://api.medos.oneUse a dedicated test key, and put your browser's address on its allowlist
A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.
Request
curl -sX POST "https://api.medos.one/v1/otp/send" \
-H "x-api-key: $MEDOS_API_KEY" \
-H "x-end-user-id: $PATIENT_ID" \
-H "Content-Type: application/json" \
-d '{ "countryCode": "+91", "phoneNumber": "9876543210" }'Response
{
"success": true,
"message": "OTP sent successfully",
"channel": "whatsapp",
"phoneNumber": "+91****10"
}The destination is masked, and always reported under phoneNumber — on the
email channel that field holds a masked address. Read channel to know which.
Rate limits
| Bucket | Limit |
|---|---|
| Per destination | 3 codes per 10 minutes |
Per end user (x-end-user-id), per workspace | 50 codes per 24 hours |
Both answer 429 with a real Retry-After. Honour it rather than inventing a
backoff — see the note on end users
about why each patient needs their own x-end-user-id.
Common failures
| Status | Cause |
|---|---|
400 | No phoneNumber (or email on the email channel). |
400 | channel is neither whatsapp nor email. |
400 | Delivery failed. |
429 | One of the buckets above. |
Next
Verify an OTP
Check the code and open the gate.