curl --request POST \
--url https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"code": "123456"
}
'import requests
url = "https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm"
payload = { "code": "123456" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({code: '123456'})
};
fetch('https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'code' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm"
payload := strings.NewReader("{\n \"code\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"code\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"code\": \"123456\"\n}"
response = http.request(request)
puts response.read_body{
"id": "6a9fee5c215e5530b3530e78",
"email": "user@example.com",
"firstName": "John",
"signedUpAt": "2026-09-08T11:15:40.932Z",
"timezone": "America/New_York",
"notificationPreferences": [
{
"type": "cardTransaction.approved",
"email": true,
"mobile": false
}
],
"verification": {
"status": "not_started",
"country": "US",
"requirement": {
"type": "identity_verification",
"status": "not_started",
"description": "Verify your identity to unlock payment features",
"actionUrl": "https://verify.example.com/start",
"retryable": true
}
},
"capabilities": [
{
"product": "fiat_to_crypto",
"name": "ACH Bank Transfer",
"description": "Buy crypto using ACH bank transfer",
"status": "active",
"requirements": [],
"method": "ach_credit",
"nextRequirement": "identity_verification"
}
]
}{
"title": "Unauthorized",
"status": 401,
"type": "urn:problem-type:auth:unauthorized",
"detail": "Bearer token required",
"instance": "<string>",
"realm": "API",
"scope": "read:users"
}{
"title": "Unauthorized",
"status": 400,
"type": "urn:problem-type:auth:unauthorized",
"detail": "<string>",
"instance": "/errors/1234567890",
"code": "transaction_limit",
"field": "amountUsd",
"retryable": true,
"retryAfter": 5,
"suggestedAction": "auto_ramp",
"clearsAt": "2023-11-07T05:31:56Z",
"availableAt": "2023-11-07T05:31:56Z",
"permanent": true
}Confirm an email update
Confirms a pending email update session with the code sent to the new email address and returns the updated user profile.
curl --request POST \
--url https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"code": "123456"
}
'import requests
url = "https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm"
payload = { "code": "123456" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({code: '123456'})
};
fetch('https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'code' => '123456'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm"
payload := strings.NewReader("{\n \"code\": \"123456\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"code\": \"123456\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://platform.spritz.finance/v1/users/me/email-update-sessions/{sessionId}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"code\": \"123456\"\n}"
response = http.request(request)
puts response.read_body{
"id": "6a9fee5c215e5530b3530e78",
"email": "user@example.com",
"firstName": "John",
"signedUpAt": "2026-09-08T11:15:40.932Z",
"timezone": "America/New_York",
"notificationPreferences": [
{
"type": "cardTransaction.approved",
"email": true,
"mobile": false
}
],
"verification": {
"status": "not_started",
"country": "US",
"requirement": {
"type": "identity_verification",
"status": "not_started",
"description": "Verify your identity to unlock payment features",
"actionUrl": "https://verify.example.com/start",
"retryable": true
}
},
"capabilities": [
{
"product": "fiat_to_crypto",
"name": "ACH Bank Transfer",
"description": "Buy crypto using ACH bank transfer",
"status": "active",
"requirements": [],
"method": "ach_credit",
"nextRequirement": "identity_verification"
}
]
}{
"title": "Unauthorized",
"status": 401,
"type": "urn:problem-type:auth:unauthorized",
"detail": "Bearer token required",
"instance": "<string>",
"realm": "API",
"scope": "read:users"
}{
"title": "Unauthorized",
"status": 400,
"type": "urn:problem-type:auth:unauthorized",
"detail": "<string>",
"instance": "/errors/1234567890",
"code": "transaction_limit",
"field": "amountUsd",
"retryable": true,
"retryAfter": 5,
"suggestedAction": "auto_ramp",
"clearsAt": "2023-11-07T05:31:56Z",
"availableAt": "2023-11-07T05:31:56Z",
"permanent": true
}Authorizations
User bearer credential: either a Cognito JWT or an ak_ user API key. Backend integrators using HMAC must include the user API key alongside the three HMAC headers on user-scoped endpoints.
Path Parameters
Identifier returned when the email update session was created.
1Body
Confirms a pending email update session and applies the new email address to the current account.
Confirms a pending email update session and applies the new email address to the current account.
Six-digit confirmation code sent to the new email address.
6^[0-9]{6}$"123456"
Response
Response for status 200
Unique identifier for the user
"6a9fee5c215e5530b3530e78"
User's email address
"user@example.com"
User's first name
"John"
ISO 8601 timestamp of when the user was created
"2026-09-08T11:15:40.932Z"
User's timezone in IANA format
"America/New_York"
User's notification preferences by type
Show child attributes
Show child attributes
User's identity verification status and any pending requirements
Show child attributes
Show child attributes
User's available capabilities and their requirements
Show child attributes
Show child attributes