Account authorization
Start QR authentication
Starts a QR login flow for providers using auth_mode=qrcode. Poll /auth or call /auth/qr/check to retrieve the QR content; for some providers the QR is delivered asynchronously over webhook instead of synchronously in the response body.
https://api.unifyport.ai/v1/accounts/{account_id}/auth/qr/startBefore you call
Use a server-side X-Api-Key for the workspace that owns the resource. Replace every placeholder before running a sample.
Prepare your parameters
- account_id
- Use data.id from account creation or an account query. Account identifiers belong to the workspace selected by X-Api-Key. Get account
Request parameters
Headers
X-Api-KeyWorkspace API key. The workspace is resolved from this header.
Content-TypeUse application/json when sending a JSON request body.
Path parameters
account_idIdentifier used in the authentication route.
Request body
This endpoint accepts an empty JSON object; send {} exactly as shown in the request example.
Understand the result
Use the documented response fields and HTTP status. Successful 204 responses have no body; use X-Request-Id for diagnosis. Follow the related operations for the next step.
Response 200 OK
{
"request_id": "<REQUEST_ID>",
"data": {
"account_id": "acc_example",
"status": "awaiting_qr_scan",
"auth_payload": {
"qr_code": "https://example.com/qr"
},
"expires_at": "2026-01-01T00:00:00Z"
}
}
Response body
account_idProvider account this response refers to.
providerChannel identifier. Use the API value unchanged in later calls; see the enum below for the values returned by this endpoint.
actionRuntime action that was requested.
statusCurrent authorization flow status, for example pending_auth, awaiting_qr_scan, awaiting_code, pending, passkey_required, passkey_pending, passkey_confirmation, passkey_confirmation_sent, authorized, or failed.
auth_statusNormalized authentication state returned by the Passkey action.
auth_payloadStandard payload needed for the current step. QR uses qr_code; code verification uses type=code; Passkey uses type=passkey and public_key. Mutually exclusive step payloads do not appear together.
expires_atRFC3339 timestamp after which the current auth_payload is no longer valid.
Responses
200200 OK
Request succeeded. See the example response body.
400Bad Request
The request body, path, or parameters are invalid.
401Unauthorized
The X-Api-Key header is missing or invalid.
409Conflict
The requested operation conflicts with an existing provider account or resource.
500Internal Server Error
The service encountered an unexpected error.
502Bad Gateway
The provider adapter or upstream provider could not complete the operation.
If the request fails
Inspect HTTP status and error.code/numeric_code, and keep request_id for diagnosis. Correct invalid parameters, complete required authorization or check runtime state as appropriate. Confirm the outcome before retrying a send or another write. Error reference
- invalid_request · 10000 · 400
- Check required fields, formats and channel conditions, then correct the request.
- invalid_api_key · 11001 · 401
- Check X-Api-Key and whether the workspace is active.