> ## Documentation Index
> Fetch the complete documentation index at: https://hfsaa.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Confirm an application email address

> Consumes the one-time token only after the person submits the confirmation form, preventing email scanners from using it.



## OpenAPI

````yaml /openapi.yaml post /v1/developer/verify
openapi: 3.1.0
info:
  title: HFSAA Public API
  version: 1.2.2
  description: >
    API-key protected access to HFSAA-certified restaurants, meat markets, and
    dining halls.

    Every directory-data route in the `/v1` namespace requires an API key; there
    are no

    anonymous data endpoints. Public health and developer-onboarding routes are
    explicitly

    marked with `security: []` and do not expose directory data.

    Developers can request test access without creating an account. Test keys do
    not

    expire automatically, but they are restricted to the test environment and
    quota.

    Successful data responses may be cached privately for no more than one hour.
  contact:
    name: HFSAA
servers:
  - url: https://api.hfsaa.org
    description: Production
  - url: https://hfsaa-public-api-staging.idris-ocasio.workers.dev
    description: Test
security:
  - ApiKeyAuth: []
paths:
  /v1/developer/verify:
    post:
      tags:
        - Developer Access
      summary: Confirm an application email address
      description: >-
        Consumes the one-time token only after the person submits the
        confirmation form, preventing email scanners from using it.
      operationId: verifyDeveloperApplication
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
                - token
              properties:
                token:
                  type: string
      responses:
        '200':
          description: Email verified; the application is pending review.
        '400':
          description: The token is invalid, expired, or already used.
      security: []
components:
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: hfsaa_test_... or hfsaa_live_...
      description: 'Use the API key as `Authorization: Bearer <api-key>`.'

````