Before using the OTV endpoint, the following conditions must be met:
- The client's account must have the Client Config enabled, OneTimeVerification and Public API set to true. This is controlled by a --ProviderTrust admin and can be toggled per client.
- OTV requires at least one of the Licenses or Exclusions Monitor Products to be active on the account.
- Credential Check requires the Licenses Monitor Product to be active.
- API key authentication is required on all requests. If the client's key does not have OTV access, a 401 Unauthorized is returned with a descriptive error message.
- Enable AMS flag in Launch Darkly for the individual clients on OTV.
Note: If your account does not have OTV enabled, contact your ProviderTrust representative to have the flag turned on.