> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scripxhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorize a firm

> Complete API-driven verification of a ScripX client firm with the one-time authorization code sent to the firm's registered email and mobile.

Completes a [verification](/api-reference/firms/verify) that returned `verification_pending`: pass the one-time authorization code the firm received on its registered email and mobile. On success the firm's state is `connected` and it can trade.

A wrong code keeps the firm in `verification_pending` so the firm can re-read and you can retry; lockout policy is owned server-side, never guess-loop.

### Request example

```bash theme={"dark"}
curl -X POST "https://api.scripxhq.com/v1/firms/0512345678/authorize" \
  -H "X-ScripX-Key: <YOUR_API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{"code": "482913"}'
```

### Response example

```json theme={"dark"}
{
  "firm": {
    "iec": "0512345678",
    "name": "Acme Exports Pvt Ltd",
    "state": "connected"
  }
}
```

### Errors

* `409 conflict`, the firm is not awaiting an authorization code (already connected, or verify was never called).
* `422 unprocessable`, missing `code`.

**Terms used here:** [IEC](/annexure/terminology#iec), [connection state](/annexure/terminology#connection-state), [API key](/annexure/terminology#api-key). Full list in the [terminology annexure](/annexure/terminology).

### Next steps

* The firm is live: [list its credits](/api-reference/firms/credits), [quote each](/api-reference/trading/quote), [trade](/api-reference/trading/orders-create).


## OpenAPI

````yaml POST /v1/firms/{iec}/authorize
openapi: 3.1.0
info:
  title: ScripX Partner API
  version: 1.2.0
  description: >-
    Automate duty-credit-scrip trading: quote, order, positions, market,
    webhooks. Auth: `X-ScripX-Key: scripx_live_…`. Money = integer paise; price
    = bps of face.
  contact:
    name: ScripX API Support
    email: amin@eximfiles.io
    url: https://scripxhq.com
servers:
  - url: https://api.scripxhq.com
    description: >-
      Production and sandbox share one host; a scripx_test_ key selects the
      sandbox.
security:
  - ApiKeyAuth: []
tags:
  - name: Firms
    description: >-
      client-firm lifecycle: register, verify, authorize, credits, update,
      offboard
  - name: Trading
    description: quote, orders, positions, market
  - name: Group
    description: intra-group netting + positions (enterprise/broker)
  - name: Cross
    description: 'broker cross-desk: block deals + intra-group transfers'
  - name: Webhooks
    description: event subscriptions + delivery
  - name: Account
    description: usage + metering
  - name: Keys
    description: self-serve scoped child keys (sub-accounts)
paths:
  /v1/firms/{iec}/authorize:
    post:
      tags:
        - Firms
      summary: Complete verification with the one-time authorization code
      parameters:
        - name: iec
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/FirmAuthorizeRequest'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FirmRecord'
        '401':
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    FirmAuthorizeRequest:
      type: object
      required:
        - code
      properties:
        code:
          type: string
          description: the one-time authorization code the firm received
    FirmRecord:
      type: object
      properties:
        firm:
          $ref: '#/components/schemas/Firm'
    Error:
      type: object
      properties:
        error:
          type: string
        code:
          type: string
          description: stable machine code
          enum:
            - bad_request
            - unauthorized
            - forbidden
            - not_found
            - conflict
            - unprocessable
            - rate_limited
            - internal
        message:
          type: string
        detail:
          type: object
    Firm:
      type: object
      properties:
        iec:
          type: string
        name:
          type: string
        email:
          type: string
        role:
          type: string
          enum:
            - exporter
            - importer
        state:
          type: string
          enum:
            - registered
            - connecting
            - verification_pending
            - connected
            - attention_needed
            - reconnect_needed
        created_at:
          type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-ScripX-Key
      description: >-
        Your API key, e.g. `scripx_live_…`. Bound to one firm; tenant isolation
        is enforced.

````