This API uses a Bearer key and plain JSON, with no signing. Its approval rules are the same as the Auth API.
Basics
| Topic | Rule |
|---|---|
| Base URL | https://auth.wiracode.com/v1/integrations |
| Authentication | Authorization: Bearer wpk_<prefix>_<secret> |
| Bodies | JSON (Content-Type: application/json), at most 128 KiB. |
| Errors | {"error": "NOT_ENROLLED", "message": "…"}. error is the machine code; extra data such as until and retryAfterSec sits at the top level. |
This API and the Auth API share the same approval requests. A txid from the Auth API can be read with GET /v1/integrations/requests of the same integration, and the other way round.
Endpoints
Can This User Be Asked for Approval?
POST/v1/integrations/check
Header Authorization: Bearer wpk_….
ready is true when an active approval phone is signed in to WiraPass. An unknown email answers all zeros.
| Parameter | In | Required | Description |
|---|---|---|---|
email | JSON | Yes | The user's WiraPass email. |
Answer 200. Readiness of the user.
{
"ready": true,
"devices": 2,
"signedInDevices": 1,
"backupCode": true
}Errors: UNAUTHORIZED, INVALID_EMAIL, RATE_LIMITED (meaning).
Send an Approval Request
POST/v1/integrations/requests
Header Authorization: Bearer wpk_….
Creates a request and pushes it to the user's signed-in phones.
| Parameter | In | Required | Description |
|---|---|---|---|
email | JSON | Yes | The user's WiraPass email. |
title | JSON | No | Title on the phone. Default: "Masuk ke <integration name>". |
context | JSON | No | Only app, account, ip, location, device; each at most 120 characters. |
ttlSeconds | JSON | No | Request lifetime, 30 to 300 seconds, default 60. |
Answer 201. Created. delivered = pushes accepted by FCM (0 is possible).
{
"id": "3f2b8c1e-5d4a-4e6f-9a7b-1c2d3e4f5a6b",
"expiresAt": "2026-09-27T08:17:00.000Z",
"delivered": 1
}Errors: UNAUTHORIZED, INVALID_EMAIL, RATE_LIMITED, NOT_ENROLLED, NO_SIGNED_IN_DEVICE, FROZEN, TOO_MANY_PENDING (meaning).
Status of a Request
GET/v1/integrations/requests
Header Authorization: Bearer wpk_….
Only approved means yes. reported means the user pressed "Not me".
| Parameter | In | Required | Description |
|---|---|---|---|
id | query | Yes | Request id. |
wait | query | No | Long-poll 0 to 25 seconds. |
Answer 200. Current status.
{
"id": "3f2b8c1e-5d4a-4e6f-9a7b-1c2d3e4f5a6b",
"status": "approved",
"expiresAt": "2026-09-27T08:17:00.000Z",
"answeredAt": "2026-09-27T08:16:21.412Z",
"reason": null
}Errors: UNAUTHORIZED, NOT_FOUND, RATE_LIMITED (meaning).
Cancel a Request
POST/v1/integrations/cancel
Header Authorization: Bearer wpk_….
Cancels a pending request, for example when the user chose a backup code.
| Parameter | In | Required | Description |
|---|---|---|---|
id | JSON | Yes | Request id. |
Answer 200. Status after cancelling.
{
"id": "3f2b8c1e-5d4a-4e6f-9a7b-1c2d3e4f5a6b",
"status": "cancelled",
"expiresAt": "2026-09-27T08:17:00.000Z",
"answeredAt": "2026-09-27T08:16:05.000Z",
"reason": "integration"
}Errors: UNAUTHORIZED, NOT_FOUND, RATE_LIMITED (meaning).
Check a Backup Code
POST/v1/integrations/backup-code
Header Authorization: Bearer wpk_….
For phones without internet. A wrong or used code and an unknown email get the same answer.
| Parameter | In | Required | Description |
|---|---|---|---|
email | JSON | Yes | The user's WiraPass email. |
code | JSON | Yes | The 6-digit backup code. |
Answer 200. The code is right.
{
"ok": true
}Errors: UNAUTHORIZED, WRONG_CODE, CODE_LOCKED, RATE_LIMITED (meaning).