> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vort-sourcing.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Redeem a one-time activation code for an org token

> Single-use. A second redeem of the same code returns 409 `code_already_redeemed`;
the org token is not returned again. Not safe to retry blindly after a timeout.




## OpenAPI

````yaml /api-reference/openapi.yaml post /activations/redeem
openapi: 3.1.0
info:
  title: Vort Partner API
  version: 1.0.0
  summary: Server-to-server API for ATS vendors embedding Vort candidate matching.
  description: >
    Guides: [Integration flow](/integration-flow). UI rules: [UI
    specification](/ui-specification). Notices: [Notices](/notices).


    - Every call is server-to-server. `vpk_` keys and `vot_` org tokens MUST NOT
    reach a browser.

    - Clients MUST ignore unknown response fields; additive changes within v1
    are non-breaking.

    - Notices with an unknown `code` MUST be rendered generically from `title` +
    `body`,
      styled by `severity`, placed by `slot`.
    - Rate limits are per partner (default 120/minute, 20,000/day); `429`
    carries `Retry-After`.

    - Sandbox ([Sandbox guide](/sandbox)): every sandbox response carries
    `x-vort-environment: sandbox`;
      names are masked, reveals are synthetic and free, `target_count` <= 20, 20 real runs
      per organization per 24 h, `cert-*` jobs run certification fixtures, and the
      sandbox-only headers `x-vort-sandbox-simulate` / `x-vort-sandbox-reveal-price` and
      route `POST /sandbox/webhooks/test` exist. None of these exist in production.
  contact:
    name: Vort partner support (always include the run_id)
  license:
    name: Proprietary
    identifier: LicenseRef-Vort-Proprietary
servers:
  - url: https://vort-partner-api.vercel.app/sandbox/v1
    description: Sandbox
security:
  - partnerKey: []
    orgToken: []
tags:
  - name: Activation
    description: Connect a customer organization by redeeming its one-time activation code.
  - name: Users
    description: Register the recruiters who act on runs (a field, never a credential).
  - name: Jobs
    description: Jobs the runs search for.
  - name: Runs
    description: Start runs and read their progress, notices and candidates.
  - name: Candidates
    description: Reveal candidate contact details (charges credits).
  - name: Decisions
    description: Report recruiter decisions and the notices shown (mandatory).
  - name: Sandbox
    description: >-
      Sandbox-only helpers (see the [Sandbox guide](/sandbox)). Not present in
      production (404).
  - name: Webhooks
    description: >-
      Events Vort posts to your registered HTTPS endpoint, signed with
      `x-vort-signature`.
paths:
  /activations/redeem:
    post:
      tags:
        - Activation
      summary: Redeem a one-time activation code for an org token
      description: >
        Single-use. A second redeem of the same code returns 409
        `code_already_redeemed`;

        the org token is not returned again. Not safe to retry blindly after a
        timeout.
      operationId: redeemActivationCode
      parameters:
        - $ref: '#/components/parameters/Lang'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RedeemRequest'
            example:
              code: VORT-7KQM-3XHP
              external_id: hrmony-tenant-5521
      responses:
        '200':
          description: Redeemed. `org_token` is returned once; store it server-side.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RedeemResponse'
              example:
                organization_id: 0b8f4a52-2d1e-4c7b-9a61-5f0e3c2d9b17
                org_token: vot_9c1e0000000000000000000000000000000000000000abcd
                organization_name: Acme Staffing Ltd
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: '`code_not_found`'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: code_not_found
                message: This activation code does not exist.
        '409':
          description: '`code_already_redeemed` (with `redeemed_at`) or `external_id_taken`'
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/CodeAlreadyRedeemedError'
                  - $ref: '#/components/schemas/Error'
              examples:
                alreadyRedeemed:
                  value:
                    error: code_already_redeemed
                    message: This activation code was already used.
                    redeemed_at: '2026-10-01T07:40:12Z'
                externalIdTaken:
                  value:
                    error: external_id_taken
                    message: >-
                      This external_id is already connected to a Vort
                      organization.
        '410':
          description: '`code_expired`'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          $ref: '#/components/responses/RateLimited'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
      security:
        - partnerKey: []
components:
  parameters:
    Lang:
      name: x-vort-lang
      in: header
      required: false
      description: Language of notices and messages. Defaults to the partner default.
      schema:
        type: string
        enum:
          - he
          - en
  schemas:
    RedeemRequest:
      type: object
      required:
        - code
        - external_id
      properties:
        code:
          type: string
          description: >-
            As typed, e.g. VORT-7KQM-3XHP. Case, spaces and dashes are
            normalized.
          examples:
            - VORT-7KQM-3XHP
        external_id:
          type: string
          description: Your id for this customer. Unique per partner.
          minLength: 1
    RedeemResponse:
      type: object
      required:
        - organization_id
        - org_token
        - organization_name
      properties:
        organization_id:
          type: string
          format: uuid
        org_token:
          type: string
          pattern: ^vot_[0-9a-f]{48}$
          description: Returned once. Store server-side, encrypted.
        organization_name:
          type: string
    Error:
      type: object
      description: >-
        Error envelope. Branch on `error`; unknown codes are handled by HTTP
        status.
      required:
        - error
        - message
      properties:
        error:
          type: string
          examples:
            - invalid_partner_key
            - invalid_org_token
            - partner_disabled
            - organization_disabled
            - rate_limited
            - rate_limit_unavailable
            - code_not_found
            - code_expired
            - external_id_taken
            - invalid_user
            - job_not_found
            - user_not_found
            - run_not_found
            - candidate_not_in_run
            - invalid_decision
        message:
          type: string
      additionalProperties: true
    CodeAlreadyRedeemedError:
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          required:
            - redeemed_at
          properties:
            error:
              const: code_already_redeemed
            redeemed_at:
              type: string
              format: date-time
  responses:
    Unauthorized:
      description: '`invalid_partner_key` or `invalid_org_token`'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: invalid_org_token
            message: The organization token is not valid.
    Forbidden:
      description: '`partner_disabled` or `organization_disabled`'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: organization_disabled
            message: This organization's Vort connection is disabled.
    RateLimited:
      description: '`rate_limited`'
      headers:
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: rate_limited
            message: Too many requests.
    ServiceUnavailable:
      description: >-
        `rate_limit_unavailable` — the rate limiter could not be checked, so the
        request was refused rather than let through unmetered. Retry with
        backoff.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: rate_limit_unavailable
            message: Rate limiting is temporarily unavailable. Retry shortly.
  headers:
    RetryAfter:
      description: Seconds to wait before retrying.
      schema:
        type: integer
        minimum: 0
  securitySchemes:
    partnerKey:
      type: apiKey
      in: header
      name: x-partner-key
      description: 'Partner API key: `vpk_live_` + 48 lowercase hex. Server-side only.'
    orgToken:
      type: apiKey
      in: header
      name: x-vort-org
      description: >-
        Customer org token: `vot_` + 48 lowercase hex, from /activations/redeem.
        Server-side only.

````