Skip to main content
A verification email can carry a 6-digit code, a link, or both - decided by the tenant’s own configuration, not by this call. There’s also one legacy single-token method, kept for compatibility.
sendVerificationEmail() still takes a 'code' | 'link' first argument for backward compatibility, but it’s never sent to the server - passing it has no effect.
needsTokenRefresh: true means the access token’s email_verified claim is now stale - call refreshToken() to get one that reflects the new status.

Legacy single-token verify

Prefer the code/link flow above for new integrations - this is the older, simpler variant kept for compatibility.