Confirm an alert email
Enter the code sent to a new alert address, so payment alerts go there.
Moves your alerts to pending_alert_email with the code emailed there, which shows the address reaches you. Alerts go there from now on, pending_alert_email goes back to null, and you receive business.updated. It takes a person signed in to the dashboard, never an API key.
Path
idstring RequiredThe business's ID, such asbiz_Nq4sT8vWx2Lm6Rb1.
Body
codestring RequiredThe 6-digit code from the email. Spaces don't count.
Errors
- 400
invalid_codeThe code is wrong, or isn't 6 digits.fieldiscode. - 400
code_expiredThe code is more than 15 minutes old. Send a new one. - 403
session_requiredAn API key sent the request. Only a person signed in to the dashboard can send. - 404
not_foundYou don't own a business with that ID. - 409
verification_expiredNo alert address is waiting: it was confirmed, canceled or replaced, or it's more than 24 hours old. Enter it again withPATCH /businesses/{id}. - 429
too_many_attempts5 wrong tries used up the code. Send a new one.
Any request can also fail on its key or its body. See errors.
RequestBrowser
// On a dashboard page, whose session cookie the browser sends.const response = await fetch("/api/v1/businesses/biz_Nq4sT8vWx2Lm6Rb1/alert-email/confirm", { method: "POST", headers: { "402pay-Business": businessId, "Content-Type": "application/json", }, body: JSON.stringify({ code: "305817" }),});const { data } = await response.json();Response200 OK
{ "data": { "id": "biz_Nq4sT8vWx2Lm6Rb1", "kind": "business", "name": "Acme Studio", "website": "https://example.com", "support_email": "billing@example.com", "alert_email": "alerts@example.com", "pending_alert_email": null, "status": "active", "suspended_at": null, "email_alerts": true, "product_updates": false, "created_at": "2026-05-09T21:18:42.216Z", "updated_at": "2026-09-28T14:07:33.905Z" }}