Skip to main content
POST
Verify Debit Wallet
Use this API to complete a debit transaction that requires OTP verification. Call this API after the Debit Wallet API returns status_code: OTP_GENERATED for SMALL_PPI or FULL_KYC_PPI sub-wallets. The request accepts two fields: debit_id and otp.
Refer to Status and status-code reference for a comprehensive list of status and status_code combinations.
A maximum of three verification attempts is allowed per debit_id. Further attempts return an error.

Authorizations

x-client-id
string
header
required

Your unique client identifier issued by Cashfree. You can find this in your Merchant Dashboard.

x-client-secret
string
header
required

The secret key associated with your client ID. Use this to authenticate your API requests. You can find this in your Merchant Dashboard.

Headers

x-api-version
string
default:2025-11-01
required

API version to be used. Format is in YYYY-MM-DD.

Example:

"2025-11-01"

Body

application/json

Request parameters to verify the OTP for a wallet debit request.

debit_id
string
required

Unique identifier for the debit transaction, as supplied when you created the debit via Debit Wallet (debit_id in that request).

Required string length: 1 - 50
Example:

"DEBIT420984"

otp
string
required

One-time password received by the end user on the notification channels configured in auth.data.notification_modes on the original Debit Wallet request.

Required string length: 4 - 10
Example:

"222113"

Response

Success response for verifying a wallet debit OTP.

debit_id
string

Unique identifier for the debit transaction, as provided by you during the debit request.

Example:

"DEBIT420984"

user_id
string

Unique identifier for the user, as provided by you during PPI user creation.

Example:

"USER827364"

cf_debit_id
string

Unique identifier for the debit transaction, generated by Cashfree.

Example:

"8901234567890123456"

wallet_id
string

Primary wallet ID from which the amount was debited.

Example:

"WALLET936721"

sub_wallet
object
applied_gift_codes
object[]

List of gift codes used in the transaction are applicable for GIFT type wallets.

status
enum<string>

Status of the debit transaction. Refer to Debit status and status-code mapping for all valid combinations.

  • For GIFT_PPI and CLOSED_LOOP_PPI sub-wallets, status is SUCCESS when the debit completes in a single call.
  • For SMALL_PPI and FULL_KYC_PPI sub-wallets, the Debit Wallet API returns status: PENDING and status_code: OTP_GENERATED until you verify the OTP using the Verify Debit Wallet API, after which status and status_code become SUCCESS.
Available options:
PENDING,
SUCCESS,
FAILED,
REJECTED,
REVERSED
Example:

"SUCCESS"

status_code
enum<string>

Status code for detailed tracking of debit progress. Refer to Debit status and status-code mapping for all valid combinations.

Available options:
PENDING,
OTP_GENERATED,
OTP_GENERATION_FAILED,
LAST_OTP_ATTEMPT_FAILED,
OTP_VERIFICATION_FAILED,
OTP_EXPIRED,
OTP_VERIFICATION_ATTEMPT_EXHAUSTED,
SUCCESS,
FAILED,
REJECTED,
REVERSED
Example:

"SUCCESS"

amount
number<double>

Amount that was debited.

Example:

600

remarks
string

Remarks for the debit transaction.

Example:

"Purchase of electronics item"

initiated_at
string<date-time>

Timestamp when the debit transaction was initiated.

Example:

"2025-07-28T10:30:00Z"

processed_at
string<date-time> | null

Timestamp when the debit transaction was processed. Returns null while the debit is awaiting OTP verification or is still in progress.

Example:

"2025-07-28T10:30:00Z"

notes
object

Optional key-value pairs for any extra information. Keys and values must be strings. The following constraints apply:

  • Maximum 10 entries.
  • Keys: maximum 50 characters. Alphanumeric characters, underscores (_), periods (.), commas (,), single quotes ('), ampersands (&), hyphens (-), and spaces are allowed.
  • Values: maximum 200 characters. Same character set as keys.
auth
object

Present only when you sent auth in the Debit Wallet request body for an OTP flow (SMALL_PPI or FULL_KYC_PPI). Echoes the same mode and data you supplied. Omitted for single-step debits (such as GIFT_PPI or CLOSED_LOOP_PPI).