SMS Verification

SMS verification code capability: sending and verification via Aliyun phone number authentication, with codes generated/validated server-side to prevent SMS bombing. The Aliyun channel is currently integrated.

/api/sms_verify/

Service Description

The SMS verification service is built on Alibaba Cloud phone-number authentication, with the server generating, sending and checking codes: call the send API to deliver a code to a mobile number, then call the check API once the user enters it to see whether it is correct or has expired.

Integrators can configure the code length, validity period, duplicate-send policy and throttling interval (60 seconds by default) to prevent SMS abuse. Verification happens on Alibaba Cloud's side, so you do not need to store or compare codes yourself.

All endpoints require project signature authentication, and the request body must be an application/x-www-form-urlencoded form rather than a JSON body.

Aliyun SMS Verification Code

Aliyun Phone Number Authentication Service (Dypnsapi) Signature Required

Verification codes are dynamically generated and verified by the Aliyun system; all APIs require the project Signature to prevent SMS abuse.

POST /api/sms_verify/aliyun/send Total calls: 0

Send SMS Verification Code

Send an SMS verification code to the specified phone number; the validity period, rate limit interval and more are configurable.

11-digit phone number (Required)

Optional: 4-8, Default 4

Optional: verification code validity period, Default 300 seconds (5 minutes)

Optional: Default 1 (overwrite the old code)

Optional: rate limit interval, Default 60 seconds (anti SMS bombing)

Optional: 1-7 (1 = digits only), Default 1

Optional: enable true only for testing, so you can retrieve the code directly for verification

Optional: leave empty to use the Aliyun default scheme

Optional: external transaction ID (passed through in the response)

  • The request body is an application/x-www-form-urlencoded form; this service requires the project Signature (app_id/timestamp/nonce/sign).
  • A successful send returns code=10000; when the rate limit is triggered, the response asks you to wait (interval seconds) before retrying.
POST /api/sms_verify/aliyun/check Total calls: 0

Verify SMS Verification Code

Verify whether the verification code entered by the user is correct or has expired.

11-digit phone number (Required)

Verification code received on the phone (Required)

Optional: Default 1 (case-insensitive)

Optional: must match the value used when sending the code; leave empty to use the default scheme

Optional: external transaction ID (passed through in the response)

  • A successful API request always returns code=10000; the business result is determined by data.verify_result:
  • PASS = verification succeeded, UNKNOWN = verification failed (wrong or expired verification code).
XiaoYingAPI · Unified API Aggregation Service