Resend a Verification Link
Mints a fresh one-time hosted link for the same attempt and re-delivers it to the
subject’s email when one is on file. Use when the previous link expired unused or never
arrived. Fails with 422 on attempts in a terminal state (approved, declined, expired,
revoked) — open a new attempt via re-verify instead.
Authorizations
Per-request DPoP proof JWT (RFC 9449). MUST accompany the Authorization: DPoP <access_token> header on every protected operation. The proof is signed by the merchant's private DPoP key and carries htm, htu, iat, jti, and ath claims.
Headers
Unique key identifying this operation. Sending the same key twice returns the original response instead of creating a duplicate. Keys are retained for 24 hours.
255Path Parameters
Verification attempt ID.
^vrf_[a-zA-Z0-9]+$Response
Fresh link minted (secret-once, in hosted_link).
One verification attempt. hosted_link is secret-once: present only on the response
that minted it (create / resend / regenerate / re-verify) and never on a read.