> ## Documentation Index
> Fetch the complete documentation index at: https://hoalulab.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Xác thực OTP



## OpenAPI

````yaml /vi/openapi/dnse.2026-09-15.openapi.yaml post /registration/trading-token
openapi: 3.0.0
info:
  title: DNSE OpenAPI (2026-09-15)
  version: 2.0.0
  description: DNSE OpenAPI spec
servers:
  - url: https://openapi.dnse.com.vn
    description: Production
  - url: https://sb-openapi.dnse.com.vn
    description: Sanbox
security: []
tags:
  - name: trading
    description: Xác thực và các hoạt động đặt lệnh.
    x-group: Giao dịch
  - name: account
    description: Tài khoản, số dư, khoản vay, lệnh và vị thế.
    x-group: Tài khoản
  - name: market
    description: Thông tin mã chứng khoán, báo giá, OHLC và giao dịch.
    x-group: Dữ liệu thị trường
paths:
  /registration/trading-token:
    post:
      tags:
        - trading
      summary: Xác thực OTP
      operationId: registration_getTradingToken
      parameters:
        - $ref: '#/components/parameters/XApiKey'
        - $ref: '#/components/parameters/XAuxDate'
        - $ref: '#/components/parameters/XSignature'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TradingTokenRequest'
            example:
              otpType: email_otp
              passcode: '569542'
      responses:
        '200':
          description: OK
          headers:
            Content-Length:
              $ref: '#/components/headers/ContentLength'
            Date:
              $ref: '#/components/headers/Date'
            Vary:
              $ref: '#/components/headers/Vary'
            X-Frame-Options:
              $ref: '#/components/headers/XFrameOptions'
            X-Ratelimit-Limit:
              $ref: '#/components/headers/XRateLimitLimit'
            X-Ratelimit-Remaining:
              $ref: '#/components/headers/XRateLimitRemaining'
            X-Ratelimit-Reset:
              $ref: '#/components/headers/XRateLimitReset'
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
            X-Tyk-Api-Expires:
              deprecated: false
              schema: {}
              example: Thu, 02 Jan 3000 15:04:00 UTC
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TradingTokenResponse'
              example:
                tradingToken: 9ab81e9c-8a81-45aa-8190-b69a1c179d52
        '400':
          $ref: '#/components/responses/BadRequest'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    XApiKey:
      name: X-Api-Key
      in: header
      required: true
      description: >-
        API key được cấp khi đăng ký dịch vụ DNSE OpenAPI.

        Ví dụ:
        `b3JnOmRuc2UgaWQ6MjdlZTc1MzcxZGFkNTY0NmYzYTM2NDk1ZGE3OGNiOGQgaDptdXJtdXIxMjg=`
      schema:
        type: string
    XAuxDate:
      name: X-Aux-Date
      in: header
      required: true
      description: |-
        Thời gian thực hiện request, dùng trong cơ chế ký request của DNSE.
        Ví dụ: `Sat, 01 May 2026 14:24:23 +0000`
      schema:
        type: string
    XSignature:
      name: X-Signature
      in: header
      required: true
      description: >-
        Chữ ký xác thực request được tạo từ API key secret và X-Aux-Date.

        Ví dụ: `Signature
        keyId="b3JnOmRuc2UgaWQ6MjdlZTc1MzcxZGFkNTY0NmYzYTM2NDk1ZGE3OGNiOGQgaDptdXJtdXIxMjg=",algorithm="hmac-sha256",headers="(request-target)
        x-aux-date",signature="rfbVXHDUi%2B%2FsOkLXle7O17Qm%2F05cbISSR%2BDcFrBHfqQ%3D",nonce="4add8c3264e4492b9f8ecde0cf26b523"`
      schema:
        type: string
  schemas:
    TradingTokenRequest:
      type: object
      properties:
        otpType:
          type: string
          example: email_otp
          description: >-
            Phương thức xác thực OTP

            - email_otp: Áp dụng cho tài khoản đăng ký phương thức xác thực lớp
            thứ 2 là Email OTP

            - smart_otp: Áp dụng cho tài khoản đăng ký phương thức xác thực lớp
            thứ 2 là Smart OTP
        passcode:
          type: string
          example: '519752'
          description: Mã OTP tương ứng với phương thức xác thực
    TradingTokenResponse:
      type: object
      properties:
        tradingToken:
          type: string
          example: 9ab81e9c-8a81-45aa-8190-b69a1c179d52
          description: Token đặt lệnh
    ErrorBody:
      type: object
      required:
        - status
        - code
        - message
      properties:
        status:
          type: integer
          format: int32
          description: Mã HTTP.
          example: 400
        code:
          type: string
          description: Mã lỗi DNSE.
          example: OA-003
        message:
          type: string
          description: Thông điệp lỗi.
          example: Thông tin nhập không hợp lệ
  headers:
    ContentLength:
      description: Response body size in bytes.
      schema:
        type: integer
      example: 430
    Date:
      description: Response date from the DNSE gateway.
      schema:
        type: string
      example: Wed, 18 Mar 2026 16:17:35 GMT
    Vary:
      description: >-
        Response header indicating the request headers used for content
        negotiation.
      schema:
        type: string
      example: Origin
    XFrameOptions:
      description: Clickjacking protection header returned by the gateway.
      schema:
        type: string
      example: GOFORIT
    XRateLimitLimit:
      description: Maximum number of requests allowed in the current rate-limit window.
      schema:
        type: integer
      example: 300
    XRateLimitRemaining:
      description: Number of requests remaining in the current rate-limit window.
      schema:
        type: integer
      example: 299
    XRateLimitReset:
      description: Unix timestamp at which the current rate-limit window resets.
      schema:
        type: integer
      example: 1773850655
    XRequestId:
      description: Unique identifier assigned to the request by the DNSE gateway.
      schema:
        type: string
      example: unknown
  responses:
    BadRequest:
      description: Yêu cầu không hợp lệ.
      headers:
        Content-Length:
          $ref: '#/components/headers/ContentLength'
        Date:
          $ref: '#/components/headers/Date'
        Vary:
          $ref: '#/components/headers/Vary'
        X-Ratelimit-Limit:
          $ref: '#/components/headers/XRateLimitLimit'
        X-Ratelimit-Remaining:
          $ref: '#/components/headers/XRateLimitRemaining'
        X-Ratelimit-Reset:
          $ref: '#/components/headers/XRateLimitReset'
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
        X-Tyk-Api-Expires:
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            status: 400
            code: OA-003
            message: Thông tin nhập không hợp lệ
    InternalError:
      description: Lỗi hệ thống.
      headers:
        Content-Length:
          $ref: '#/components/headers/ContentLength'
        Date:
          $ref: '#/components/headers/Date'
        Vary:
          $ref: '#/components/headers/Vary'
        X-Ratelimit-Limit:
          $ref: '#/components/headers/XRateLimitLimit'
        X-Ratelimit-Remaining:
          $ref: '#/components/headers/XRateLimitRemaining'
        X-Ratelimit-Reset:
          $ref: '#/components/headers/XRateLimitReset'
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
        X-Tyk-Api-Expires:
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            status: 500
            code: OA-009
            message: Lỗi hệ thống

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.