> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spritz.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Commit email OTP start

> Submits the user's stamp for a previously prepared email-start intent. Dispatches the OTP and returns the `otpId` to pass back to the add-auth-method prepare call.



## OpenAPI

````yaml https://platform.spritz.finance/openapi.json post /v1/wallet-kit/auth-methods/email/start
openapi: 3.0.3
info:
  title: Spritz Finance API
  version: 1.0.0
  description: API for the Spritz Finance platform with RFC 9457 error handling
servers:
  - url: https://platform.spritz.finance
    description: Production
  - url: https://sandbox.spritz.finance
    description: Sandbox
security: []
tags:
  - name: Users
    description: User management endpoints
  - name: Bank Accounts
    description: Manage bank accounts for off-ramp destinations
  - name: Bills
    description: Manage bill pay accounts
  - name: Cards
    description: Spritz-issued debit cards
  - name: Auto-Ramp Accounts
    description: Virtual bank accounts that automatically convert fiat deposits to crypto
  - name: Spritz App
    description: >-
      Endpoints used by the Spritz app and internal SDKs. Excluded from the
      public partner spec.
paths:
  /v1/wallet-kit/auth-methods/email/start:
    post:
      tags:
        - Wallet Kit
      summary: Commit email OTP start
      description: >-
        Submits the user's stamp for a previously prepared email-start intent.
        Dispatches the OTP and returns the `otpId` to pass back to the
        add-auth-method prepare call.
      operationId: postV1Wallet-kitAuth-methodsEmailStart
      requestBody:
        description: >-
          Commit body for any prepared auth-method activity (add, email-start,
          remove).
        required: true
        content:
          application/json:
            schema:
              description: >-
                Commit body for any prepared auth-method activity (add,
                email-start, remove).
              type: object
              properties:
                intentId:
                  minLength: 1
                  description: Intent identifier returned by the matching prepare call.
                  type: string
                stamp:
                  minLength: 1
                  description: >-
                    Turnkey stamp produced by signing the prepared
                    `activityBody` with the user's WebAuthn authenticator.
                  type: string
              required:
                - intentId
                - stamp
          application/x-www-form-urlencoded:
            schema:
              description: >-
                Commit body for any prepared auth-method activity (add,
                email-start, remove).
              type: object
              properties:
                intentId:
                  minLength: 1
                  description: Intent identifier returned by the matching prepare call.
                  type: string
                stamp:
                  minLength: 1
                  description: >-
                    Turnkey stamp produced by signing the prepared
                    `activityBody` with the user's WebAuthn authenticator.
                  type: string
              required:
                - intentId
                - stamp
          multipart/form-data:
            schema:
              description: >-
                Commit body for any prepared auth-method activity (add,
                email-start, remove).
              type: object
              properties:
                intentId:
                  minLength: 1
                  description: Intent identifier returned by the matching prepare call.
                  type: string
                stamp:
                  minLength: 1
                  description: >-
                    Turnkey stamp produced by signing the prepared
                    `activityBody` with the user's WebAuthn authenticator.
                  type: string
              required:
                - intentId
                - stamp
      responses:
        '202':
          description: Email-start commit response. The OTP has been dispatched.
          content:
            application/json:
              schema:
                description: Email-start commit response. The OTP has been dispatched.
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      email:
                        format: email
                        description: Email the OTP was sent to.
                        type: string
                      otpId:
                        description: >-
                          OTP identifier to pass back to the add-auth-method
                          prepare call along with the OTP.
                        type: string
                    required:
                      - email
                      - otpId
                required:
                  - data
        '401':
          description: Response for status 401
          content:
            application/problem+json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 401
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                    example: Bearer token required
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  realm:
                    description: The authentication realm
                    type: string
                    example: API
                  scope:
                    description: The required scope for this resource
                    type: string
                    example: read:users
                required:
                  - title
                  - status
                additionalProperties: false
        '409':
          description: Response for status 409
          content:
            application/problem+json:
              schema:
                additionalProperties: true
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                  retryAfter:
                    description: >-
                      Seconds to wait before retrying, present alongside
                      `retryable: true`. Mirrors the `Retry-After` response
                      header and is meant for short backoffs the server chose
                      (load shedding); for a condition that clears on its own
                      schedule, `clearsAt` carries the absolute time instead.
                    type: number
                    example: 5
                  suggestedAction:
                    type: string
                    enum:
                      - auto_ramp
                      - wait_for_settlement
                  clearsAt:
                    format: date-time
                    type: string
                    description: >-
                      Earliest known time the current temporary condition may
                      clear.
                    nullable: true
                  availableAt:
                    format: date-time
                    type: string
                    description: >-
                      When a temporarily ineligible funding source may become
                      available again.
                    nullable: true
                  permanent:
                    description: >-
                      Whether the current funding-source restriction will not
                      clear automatically.
                    type: boolean
                required:
                  - title
                  - status
        '500':
          description: Response for status 500
          content:
            application/problem+json:
              schema:
                additionalProperties: true
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                  retryAfter:
                    description: >-
                      Seconds to wait before retrying, present alongside
                      `retryable: true`. Mirrors the `Retry-After` response
                      header and is meant for short backoffs the server chose
                      (load shedding); for a condition that clears on its own
                      schedule, `clearsAt` carries the absolute time instead.
                    type: number
                    example: 5
                  suggestedAction:
                    type: string
                    enum:
                      - auto_ramp
                      - wait_for_settlement
                  clearsAt:
                    format: date-time
                    type: string
                    description: >-
                      Earliest known time the current temporary condition may
                      clear.
                    nullable: true
                  availableAt:
                    format: date-time
                    type: string
                    description: >-
                      When a temporarily ineligible funding source may become
                      available again.
                    nullable: true
                  permanent:
                    description: >-
                      Whether the current funding-source restriction will not
                      clear automatically.
                    type: boolean
                required:
                  - title
                  - status
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT or ak_ user API key
      description: >-
        User bearer credential: either a Cognito JWT or an ak_ user API key.
        Backend integrators using HMAC must include the user API key alongside
        the three HMAC headers on user-scoped endpoints.

````