> ## Documentation Index
> Fetch the complete documentation index at: https://docs.optimaldial.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit a verification code

> Submits the verification code delivered by the
call or SMS triggered when the number was added (or re-sent). On success
the number becomes verified and daily monitoring begins.




## OpenAPI

````yaml https://api.optimaldial.com/openapi/v1/spec.yaml post /api/v1/spam/numbers/{number_id}/verify
openapi: 3.1.0
info:
  title: OptimalDial API
  version: '2026-08-19'
  summary: Submit phone-number lists, get them processed, receive webhooks.
  description: |
    The OptimalDial REST API lets you programmatically submit lists of phone
    numbers (CSV or JSON, 100–250,000 per request), download processed results,
    and receive HMAC-signed webhooks when uploads change state.

    Map a name column on an upload to enable **OptimalDial Identity**, which
    judges whether each number belongs to the contact named on that row and
    reports it alongside answer intent. Identity is in **public beta** — the
    output format is stable while we tune the thresholds, and feedback is very
    welcome at support@optimaldial.com.

    All endpoints require an API key as `Authorization: Bearer od_live_...`.
    Keys are minted in the in-app developer panel by an organization owner.

    See the human-readable docs at https://docs.optimaldial.com for
    quickstarts, the webhook signature verifier, and the changelog.
  contact:
    name: OptimalDial Support
    email: support@optimaldial.com
    url: https://docs.optimaldial.com
  license:
    name: Proprietary
servers:
  - url: https://api.optimaldial.com
    description: Production
security:
  - bearerAuth: []
tags:
  - name: uploads
    description: Submit, inspect, and download phone-number lists.
  - name: contacts
    description: >
      Single-contact API for per-row enrichment integrations. Available to

      every account with an API key.


      **Use `/api/v2/contacts`** — it mirrors every v1 route and additionally

      reports the nine-tier `OptimalDial_Status` and the OptimalDial Identity

      band.


      `/api/v1/contacts` is **legacy**: supported indefinitely with no removal

      planned, but its `optimaldial_status` reports the Answer Intent value
      only,

      so existing filters keep working untouched. Both versions operate on the

      same contacts — a contact created on either can be read on either, so

      moving to v2 needs no migration.

      Each `standard` contact is charged 1 credit; `max` contacts are billed so

      a batch totals `ceil(1.5 × count)` credits. Result is delivered via

      per-contact callback URL or registered webhook endpoints, and is also

      available via GET.
  - name: webhooks
    description: Register and manage webhook endpoints; inspect delivery history.
  - name: spam
    description: |
      Monitor your outbound numbers for spam/scam-likely flagging across the
      major US carriers (AT&T, T-Mobile, Verizon). Adding a number
      auto-initiates verification — required for the monitoring service
      to place test calls, not a security gate — and once the code is submitted
      OptimalDial re-tests daily, exposing per-carrier status, run history, and
      screenshots. Subscribe to the `spam.detected` and `number.verified`
      webhook events to be notified the moment a number flips to spam.
      Available to every account with an API key and an active subscription.
  - name: credits
    description: |
      Check your organization's current credit balance. Read-only and
      available to every account with an API key.
paths:
  /api/v1/spam/numbers/{number_id}/verify:
    parameters:
      - $ref: '#/components/parameters/NumberId'
    post:
      tags:
        - spam
      summary: Submit a verification code
      description: |
        Submits the verification code delivered by the
        call or SMS triggered when the number was added (or re-sent). On success
        the number becomes verified and daily monitoring begins.
      operationId: verifyMonitoredNumber
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SpamVerifyRequest'
      responses:
        '200':
          description: Code accepted; number verified.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SpamVerifyResponse'
        '400':
          description: Code is incorrect, or the number is already verified.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  parameters:
    NumberId:
      in: path
      name: number_id
      required: true
      schema:
        type: string
        format: uuid
  schemas:
    SpamVerifyRequest:
      type: object
      required:
        - code
      properties:
        code:
          type: string
          description: The verification code the recipient read back from the call/SMS.
          example: '123456'
    SpamVerifyResponse:
      type: object
      required:
        - success
        - verified
        - phone_number
        - message
      properties:
        success:
          type: boolean
        verified:
          type: boolean
        phone_number:
          type: string
          example: '+15551234567'
        message:
          type: string
    ErrorEnvelope:
      type: object
      required:
        - detail
      properties:
        detail:
          oneOf:
            - type: string
            - type: object
    RateLimitError:
      type: object
      required:
        - detail
      properties:
        detail:
          type: object
          required:
            - error
            - scope
            - limit
            - retry_after_seconds
          properties:
            error:
              type: string
              enum:
                - rate_limit_exceeded
            scope:
              type: string
              enum:
                - per_key
                - per_org
                - global
              description: >-
                Which limit was hit: the per-API-key cap, the per-organization
                cap, or the system-wide ceiling.
            limit:
              type: integer
              description: The per-minute limit for the scope that was exceeded.
            retry_after_seconds:
              type: integer
              description: >-
                Seconds to wait before retrying (also returned as the
                Retry-After header).
  responses:
    Unauthorized:
      description: Missing or invalid API key.
      headers:
        WWW-Authenticate:
          schema:
            type: string
            example: Bearer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    NotFound:
      description: Resource not found, or not visible to this API key's organization.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    RateLimited:
      description: >-
        A rate-limit bucket was exhausted (per-key, per-org, or the system-wide
        ceiling). See the `scope` field.
      headers:
        Retry-After:
          schema:
            type: integer
          description: Seconds to wait before retrying.
        X-RateLimit-Limit:
          schema:
            type: integer
          description: The per-minute limit for the scope that was exceeded.
        X-RateLimit-Remaining:
          schema:
            type: integer
          description: Tokens remaining in that bucket (0 on a 429).
        X-RateLimit-Reset:
          schema:
            type: integer
          description: Seconds until at least one token is available again.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/RateLimitError'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: od_live_xxxxxxxx
      description: >
        OptimalDial API key, prefixed `od_live_`, sent as `Authorization: Bearer
        ...`.

        Mint keys in the in-app developer panel; they are scoped to a single
        organization.

````