> ## Documentation Index
> Fetch the complete documentation index at: https://docs.valendata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Hand a run a sign-in code

> Give a waiting run the code a site texted to your phone.

When a site sends a code by text message or a phone app, the run waits up to 3 minutes. The app shows "Enter the code sent to your phone" in the run panel; from code you call this endpoint. The run types the code into the page and carries on.

If nobody sends a code in time, the run fails with `needs_user.kind = "otp_sms"`. You get `409` when the run is not waiting for a code.


## OpenAPI

````yaml POST /v1/runs/{run_id}/otp
openapi: 3.0.3
info:
  title: Valendata REST API
  version: 1.0.0
  description: >-
    Trigger Skills, manage Workflows, retrieve Runs, and stream structured
    results from any language using JSON over HTTPS.
servers:
  - url: https://api.valendata.com
    description: Production
security:
  - ApiKeyAuth: []
tags:
  - name: Skills
    description: Execute and inspect published Skills.
  - name: Workflows
    description: Trigger multi-step Workflows and list them.
  - name: Runs
    description: Start async Skill runs and read Skill and Workflow run results.
  - name: Skill creation
    description: Create a Skill from a plain-language task.
  - name: Skill improvement
    description: >-
      Fix a Skill, add fields to it or re-learn its detail steps, poll the
      result, and read its change history.
  - name: Versions
    description: List, diff, restore, and pin a Skill's recipe versions.
  - name: Webhooks
    description: Signed delivery of finished async runs.
paths:
  /v1/runs/{run_id}/otp:
    post:
      tags:
        - Logins
      summary: Hand a run a sign-in code
      description: >-
        When a site texts a sign-in code, the run waits up to 3 minutes for it.
        Send it here; the run types it into the page and carries on. Only the
        account that started the run. Needs `logins:use` on an API key.
      operationId: handRunACode
      parameters:
        - name: run_id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RunCodeRequest'
      responses:
        '202':
          description: The run has the code.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RunCodeAccepted'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: The run is not waiting for a code.
        '422':
          description: That is not a code.
      security:
        - ApiKeyAuth: []
components:
  schemas:
    RunCodeRequest:
      type: object
      required:
        - code
      properties:
        code:
          type: string
          description: The sign-in code the site sent (4–10 letters or digits).
          example: '123456'
    RunCodeAccepted:
      type: object
      properties:
        run_id:
          type: string
        accepted:
          type: boolean
    Error:
      type: object
      properties:
        detail:
          oneOf:
            - type: string
            - type: object
              additionalProperties: true
          description: >-
            Error message. Usually a plain string; may be a structured object
            for some errors.
      example:
        detail: Invalid or expired API key
  responses:
    Unauthorized:
      description: >-
        Unauthorized. The Authorization header is missing, malformed, or the
        credential is invalid or expired.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        Forbidden. You may not run or change this Skill, or it is not published
        or active.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: Resource not found in your Workspace.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: vd_sk_...
      description: >-
        API key with the `vd_sk_` prefix. Create keys from Settings, API Keys in
        the dashboard.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.