OpenAPI specification
Release: ActiveSingle operation + dependencies. Includes the request, responses, and referenced schemas for this API—not the full product specification.
Authenticate party user.
/ch/v1/party/user-authenticateUse this API to validate users with OTP and LexisNexis bot checks
Showing 8 of 8 top-level parameters (8 total fields) for Generate OTP
Client-Request-IdRequiredstringheaderUnique request correlation identifier used in HMAC signing.
TimestampRequiredstringheaderUnix epoch timestamp in milliseconds used in HMAC signing.
Auth-Token-TypeRequiredstringheaderAuthentication mechanism used by the request.
Available enum values
Selecting a value updates the request header.
AuthorizationRequiredstringheaderBase64 HMAC-SHA-256 signature; no prefix.
partyIdRequiredstringParty ID for whom the OTP is being validated
operationTypeRequiredstringThe mode of operation for the API
Available enum values
Selecting a value updates the request body.
phoneNumberstringPhone number to send OTP to including country code (E.164 format). Required for GENERATE operation; not required for VALIDATE and BOTCHECK.
modestringMode of OTP delivery. Default is sms if not specified.
Available enum values
Selecting a value updates the request body.
Request
Generate OTPResponse
Top-level fields returned in a successful (201) response.
gatewayResponseobjectGateway response and transaction state. Use transactionId or apiTraceId to track asynchronous completion.
authenticationobjectThe authentication field.
curl --request POST 'https://connect-cert.fiservapis.net/ch/v1/party/user-authenticate' \
--header 'Client-Request-Id: <Client-Request-Id>' \
--header 'Timestamp: <Timestamp>' \
--header 'Auth-Token-Type: HMAC' \
--header 'Authorization: YOUR_BASE64_HMAC_SIGNATURE' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
"operationType": "GENERATE",
"partyId": "100000000010001",
"phoneNumber": "+14153671502",
"mode": "sms"
}'| HTTP | Description |
|---|---|
| 400 | The request is invalid. |
| 401 | Authentication failed or credentials are missing. |
| 404 | The requested resource was not found. |
| 408 | The request timed out. |
| 415 | The request media type is unsupported. |
| 425 | The request was sent too early. |
| 429 | The request rate limit was exceeded. |
| 500 | An unexpected server error occurred. |
| 503 | The service is temporarily unavailable. |
| 504 | The upstream service timed out. |
Single operation + dependencies. Includes the request, responses, and referenced schemas for this API—not the full product specification.
No Postman workflow is mapped to this operation. No product-wide collection is substituted.
QA collections: Configure your environment and credentials before running. Some requests create resources or move funds.