> ## Documentation Index
> Fetch the complete documentation index at: https://docs.privue.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Initiate EPFO passbook OTP

> Send an OTP to the mobile number on a member's EPF account, to read their passbook with.

Ask the member for the OTP they receive, and send it with `details.request_id` to `/epfo/v1/passbook-submit-otp.1`. Once it is accepted, `/epfo/v1/passbook.1` reads their passbook with the same `request_id`.

A mobile number the EPFO holds no account under answers `uan-not-registered-for-mobile`, and no OTP is sent.

Only you can submit an OTP for, or read a passbook through, a request you sent, and for 30 days after you sent it: a `request_id` from a request you did not send, or from one sent longer ago, answers `404`.



## OpenAPI

````yaml /suite/api-reference/openapi.json post /epfo/v1/passbook-send-otp.1
openapi: 3.1.0
info:
  title: Privue API Suite
  version: 1.0.0
  description: >-
    Business, tax, registry, employment and identity verification against
    official Indian sources, a person's own documents read through DigiLocker
    with their consent, and an EPF member's passbook read with the OTP they
    receive.


    **Authentication.** Every request takes your API key as a bearer token:
    `Authorization: Bearer <your-key>`.


    **One envelope.** Every check returns the reasons behind a refusal and the
    record the source held, and an empty `reasons` means the check passed.
    Branch on `reasons` rather than on the status code, because a call the
    source answered returns `200` whatever it concluded.


    **DigiLocker and EPFO passbook.** A DigiLocker endpoint returns `details`
    alone: what it read, as the source holds it. So do submitting an EPFO
    passbook OTP and reading the passbook; sending the OTP answers like a check.


    **Versioning.** Each endpoint is versioned on its own, directly in its path.
    A new version of one endpoint never moves another, so no release requires
    migrating every integration at once.
servers:
  - url: https://api.privue.ai
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Checks
    description: One check on one subject, answered in the envelope every check shares.
  - name: DigiLocker
    description: >-
      A person's own documents, read through the consent they give at
      DigiLocker.
  - name: EPFO passbook
    description: >-
      A member's EPF passbook, read with the OTP sent to the mobile number on
      their account.
  - name: Orchestrated flows
    description: Every check on one business, asked and answered together in a single call.
  - name: Usage
    description: What you have called, and when.
paths:
  /epfo/v1/passbook-send-otp.1:
    post:
      tags:
        - EPFO passbook
      summary: Initiate EPFO passbook OTP
      description: >-
        Send an OTP to the mobile number on a member's EPF account, to read
        their passbook with.


        Ask the member for the OTP they receive, and send it with
        `details.request_id` to `/epfo/v1/passbook-submit-otp.1`. Once it is
        accepted, `/epfo/v1/passbook.1` reads their passbook with the same
        `request_id`.


        A mobile number the EPFO holds no account under answers
        `uan-not-registered-for-mobile`, and no OTP is sent.


        Only you can submit an OTP for, or read a passbook through, a request
        you sent, and for 30 days after you sent it: a `request_id` from a
        request you did not send, or from one sent longer ago, answers `404`.
      operationId: epfo.passbook-send-otp.1
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PassbookOtpRequest'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PassbookOtpResponse'
              examples:
                verified:
                  summary: An OTP sent
                  value:
                    reasons: []
                    details:
                      request_id: 02dece70-5967-4949-9fea-f5ce7e6a5a53
                failed:
                  summary: No EPF account under the mobile number
                  value:
                    reasons:
                      - code: uan-not-registered-for-mobile
                        message: No UAN is held under this mobile number.
                    details: null
        '401':
          description: The API key is missing, malformed or not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '403':
          description: The key is valid but is not entitled to this feature.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '422':
          description: >-
            The request failed validation, or the source would not accept the
            details in it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '429':
          description: >-
            The key is not cleared for this feature, or is sending too many
            requests. Nothing was called.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '503':
          description: >-
            The source could not be reached, or authentication is temporarily
            unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        default:
          description: The request failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
components:
  schemas:
    PassbookOtpRequest:
      properties:
        mobile:
          type: string
          pattern: ^(?:\+91)?[6-9][0-9]{9}$
          title: Mobile
          description: Mobile number on the member's EPF account, with or without +91
          examples:
            - '9876543210'
      type: object
      required:
        - mobile
      title: PassbookOtpRequest
      description: The mobile number to send the OTP to.
    PassbookOtpResponse:
      properties:
        reasons:
          items:
            $ref: '#/components/schemas/Reason'
          type: array
          title: Reasons
          description: >-
            Why the check did not pass, worst first, each a stable code with the
            text for it. Empty when it passed
        details:
          anyOf:
            - $ref: '#/components/schemas/PassbookOtp'
            - type: 'null'
          description: The request the OTP was sent for; null when no OTP was sent
      type: object
      title: PassbookOtpResponse
      description: >-
        The OTP sent, and the id the member's passbook is read by once they give
        it back.


        `details` is null when the EPFO holds no account under the mobile
        number, and no OTP is sent. That is a finding about today: the same
        request made later asks the EPFO again, and can find one.
    SuiteError:
      properties:
        code:
          type: integer
          title: Code
          description: HTTP status code of the response
        timestamp:
          type: integer
          title: Timestamp
          description: Unix millisecond timestamp of when the response was produced
        message:
          type: string
          title: Message
          description: What went wrong, in one sentence
      type: object
      required:
        - code
        - timestamp
        - message
      title: SuiteError
      description: Why a request failed.
    Reason:
      properties:
        code:
          $ref: '#/components/schemas/ReasonCode'
          description: Stable code to branch on
        message:
          type: string
          title: Message
          description: What the code means, in one sentence
      type: object
      required:
        - code
        - message
      title: Reason
      description: One machine-readable reason a check did not pass.
    PassbookOtp:
      properties:
        request_id:
          type: string
          title: Request Id
          description: >-
            Identifies this request. Send it with the OTP the member received,
            and then to read their passbook
      type: object
      required:
        - request_id
      title: PassbookOtp
      description: An OTP sent to the mobile number on a member's EPF account.
    ReasonCode:
      type: string
      enum:
        - cin-not-registered
        - gstin-not-registered
        - gstin-inactive
        - pan-inactive
        - pan-name-mismatch
        - pan-date-of-birth-mismatch
        - udyam-not-registered
        - udyam-not-registered-for-pan
        - udyam-cancelled
        - gst-not-registered-for-pan
        - company-not-registered-for-pan
        - epfo-member-not-found
        - uan-not-registered-for-pan
        - driving-licence-not-registered
        - driving-licence-details-mismatch
        - driving-licence-expired
        - uan-not-registered-for-mobile
        - passport-not-registered
        - passport-name-mismatch
        - source-unavailable
        - details-refused
        - bank-account-unverified
        - bank-account-unsettled
      title: ReasonCode
      description: >-
        Why a check did not pass, as the stable code a client branches on.


        Declared rather than written as strings so that every code a check can
        answer with reaches the published schema, and a client reads the whole
        set from the API reference.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Your API key, sent as `Authorization: Bearer <your-key>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.