API Documentation

Simple JSON API

The /v1/integrations API with a Bearer key and plain JSON.

Documentation Pages

This API uses a Bearer key and plain JSON, with no signing. Its approval rules are the same as the Auth API.

Basics

TopicRule
Base URLhttps://auth.wiracode.com/v1/integrations
AuthenticationAuthorization: Bearer wpk_<prefix>_<secret>
BodiesJSON (Content-Type: application/json), at most 128 KiB.
Errors{"error": "NOT_ENROLLED", "message": "…"}. error is the machine code; extra data such as until and retryAfterSec sits at the top level.

This API and the Auth API share the same approval requests. A txid from the Auth API can be read with GET /v1/integrations/requests of the same integration, and the other way round.

Endpoints

Can This User Be Asked for Approval?

POST/v1/integrations/check

Header Authorization: Bearer wpk_….

ready is true when an active approval phone is signed in to WiraPass. An unknown email answers all zeros.

ParameterInRequiredDescription
emailJSONYesThe user's WiraPass email.

Answer 200. Readiness of the user.

200 application/json
{
  "ready": true,
  "devices": 2,
  "signedInDevices": 1,
  "backupCode": true
}

Errors: UNAUTHORIZED, INVALID_EMAIL, RATE_LIMITED (meaning).

Send an Approval Request

POST/v1/integrations/requests

Header Authorization: Bearer wpk_….

Creates a request and pushes it to the user's signed-in phones.

ParameterInRequiredDescription
emailJSONYesThe user's WiraPass email.
titleJSONNoTitle on the phone. Default: "Masuk ke <integration name>".
contextJSONNoOnly app, account, ip, location, device; each at most 120 characters.
ttlSecondsJSONNoRequest lifetime, 30 to 300 seconds, default 60.

Answer 201. Created. delivered = pushes accepted by FCM (0 is possible).

201 application/json
{
  "id": "3f2b8c1e-5d4a-4e6f-9a7b-1c2d3e4f5a6b",
  "expiresAt": "2026-09-27T08:17:00.000Z",
  "delivered": 1
}

Errors: UNAUTHORIZED, INVALID_EMAIL, RATE_LIMITED, NOT_ENROLLED, NO_SIGNED_IN_DEVICE, FROZEN, TOO_MANY_PENDING (meaning).

Status of a Request

GET/v1/integrations/requests

Header Authorization: Bearer wpk_….

Only approved means yes. reported means the user pressed "Not me".

ParameterInRequiredDescription
idqueryYesRequest id.
waitqueryNoLong-poll 0 to 25 seconds.

Answer 200. Current status.

200 application/json
{
  "id": "3f2b8c1e-5d4a-4e6f-9a7b-1c2d3e4f5a6b",
  "status": "approved",
  "expiresAt": "2026-09-27T08:17:00.000Z",
  "answeredAt": "2026-09-27T08:16:21.412Z",
  "reason": null
}

Errors: UNAUTHORIZED, NOT_FOUND, RATE_LIMITED (meaning).

Cancel a Request

POST/v1/integrations/cancel

Header Authorization: Bearer wpk_….

Cancels a pending request, for example when the user chose a backup code.

ParameterInRequiredDescription
idJSONYesRequest id.

Answer 200. Status after cancelling.

200 application/json
{
  "id": "3f2b8c1e-5d4a-4e6f-9a7b-1c2d3e4f5a6b",
  "status": "cancelled",
  "expiresAt": "2026-09-27T08:17:00.000Z",
  "answeredAt": "2026-09-27T08:16:05.000Z",
  "reason": "integration"
}

Errors: UNAUTHORIZED, NOT_FOUND, RATE_LIMITED (meaning).

Check a Backup Code

POST/v1/integrations/backup-code

Header Authorization: Bearer wpk_….

For phones without internet. A wrong or used code and an unknown email get the same answer.

ParameterInRequiredDescription
emailJSONYesThe user's WiraPass email.
codeJSONYesThe 6-digit backup code.

Answer 200. The code is right.

200 application/json
{
  "ok": true
}

Errors: UNAUTHORIZED, WRONG_CODE, CODE_LOCKED, RATE_LIMITED (meaning).

Duo is a trademark of Cisco. WiraPass is not affiliated with Duo or Cisco and only offers API compatibility.