Verify email OTP
Verifies that the participant controls an email address by sending a one-time code and validating the entered code.
Presented context
Verify email OTP
User Journey
User response
Vue d’ensemble
Verifies that the participant controls an email address by sending a one-time code and validating the entered code.
Exemple
After collecting an email address, require proof of possession before using it for a sensitive journey step.
Key point A user action suspends the instance until the interaction is resolved. The User Journey presents the action; the node remains the orchestration contract determining its inputs and outputs.
Parameters 14
mailer
Active email configuration implementing the standard capability used to send and resend the verification code.
to
Email address to verify and to which the one-time code is sent.
title
Main title presented to the participant for this action in the User Journey.
description
Optional supporting text shown under the title to explain what is expected from the participant.
subject
Subject of the email message containing the verification code.
message_template
Markdown template for the OTP email. The runtime secret code can be injected through the variable provided by the node.
code_length
Number of digits or characters in the generated code, within node-supported bounds.
ttl_seconds
OTP validity period before expiration. A new attempt after expiration requires a new code.
resend_delay_seconds
Minimum delay between two resends to prevent overly frequent repeated sending.
max_attempts
Maximum number of code-entry attempts before verification can no longer continue normally.
max_resends
Maximum number of code resends allowed during this interaction.
mask_email_in_journey
Partially masks the email address in the User Journey to limit visual exposure.
allow_replay_from_here
Allows a participant to restart a replay from this interaction when the process enables that capability. Disable it when repeating the action would be dangerous or misleading.
replay_boundary
Marks this interaction as a replay point of no return to bound earlier steps that can be replayed or reused.
Outputs 3
verified
Confirms that the participant supplied a valid OTP code for the targeted address.
verified_email
Email address successfully verified.
verified_at
Date and time when OTP verification succeeded.
Behavior
A secret code is generated, sent through the SMTP configuration, bounded by a TTL and attempt/resend counts. The code itself is never exposed as a business output.
Limits and responsibilities
- Verification proves access to the mailbox at challenge time; it does not certify the participant's civil identity.
- The OTP code is ephemeral secret data and must not be logged or reused as business data.