Verify API
Email verification codes in two calls
Call start with an address and we email a one-time code. Call check with what the person typed and you get right, wrong or expired. You never store a code, write a resend timer or count wrong guesses.
Try it
This page calls the real API from your browser with your own key. The key stays in this tab only.
1 Your key
No key yet? Sign in with an email code; it makes an account if you don't have one.
2 Send a code
3 Check the code
Try a wrong code first: you'll see wrong_code and how many tries are left. Five wrong codes lock it.
The two calls
curl -s https://email59.com/v1/verify/start \
-H "Authorization: Bearer $EMAIL59_KEY" -H 'Content-Type: application/json' \
-d '{"to":"ada@example.org","app_name":"Acme"}'
# {"id":"vrf_...","status":"pending","expires_in_seconds":600,...}
curl -s https://email59.com/v1/verify/check \
-H "Authorization: Bearer $EMAIL59_KEY" -H 'Content-Type: application/json' \
-d '{"to":"ada@example.org","code":"482913"}'
# {"valid":true,"status":"approved",...}
The email comes from verify@email59.com (or a name you pick) with the code in the subject, so it shows in a phone's notification. Using Next.js or Supabase? The Next.js and Supabase example has both route handlers. Agents can call the verify_start and verify_check tools on the MCP server.
What email59 takes care of
| Part | How |
|---|---|
| The code | 6 digits by default (4 to 10), from a secure random generator. We keep only a hash of it, never the code itself. |
| Expiry | 10 minutes by default (1 to 60). A right code works once. |
| Wrong guesses | Five wrong codes lock it; the person asks for a new one. |
| Resends | One code per address every 30 seconds, at most 5 an hour. A new code replaces the old one, so only the newest works. |
| Bad addresses | Invalid, throwaway and blocked addresses are refused before anything is sent. |
| Answers | check always answers 200 with valid and a status: approved, wrong_code, expired, too_many_attempts, already_used, replaced or not_found. |
Full reference in the docs.
Add email codes to your app today
No domain to set up, no SMTP server, no subscription.