Verify Passkey Registration
Finish the process of registering a new passkey authenticator.
curl --request POST \
--url https://api.authsignal.com/v1/client/user-authenticators/passkey \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"challengeId": "<string>",
"registrationCredential": {},
"conditionalCreate": true
}
'import requests
url = "https://api.authsignal.com/v1/client/user-authenticators/passkey"
payload = {
"challengeId": "<string>",
"registrationCredential": {},
"conditionalCreate": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({challengeId: '<string>', registrationCredential: {}, conditionalCreate: true})
};
fetch('https://api.authsignal.com/v1/client/user-authenticators/passkey', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.authsignal.com/v1/client/user-authenticators/passkey",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'challengeId' => '<string>',
'registrationCredential' => [
],
'conditionalCreate' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.authsignal.com/v1/client/user-authenticators/passkey"
payload := strings.NewReader("{\n \"challengeId\": \"<string>\",\n \"registrationCredential\": {},\n \"conditionalCreate\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.authsignal.com/v1/client/user-authenticators/passkey")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"challengeId\": \"<string>\",\n \"registrationCredential\": {},\n \"conditionalCreate\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.authsignal.com/v1/client/user-authenticators/passkey")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"challengeId\": \"<string>\",\n \"registrationCredential\": {},\n \"conditionalCreate\": true\n}"
response = http.request(request)
puts response.read_body{
"isVerified": true,
"accessToken": "<string>",
"userAuthenticatorId": "<string>",
"userId": "<string>",
"userAuthenticator": {
"userAuthenticatorId": "user_authenticator_123",
"verificationMethod": "PASSKEY",
"createdAt": "2024-05-13T04:59:02.640Z",
"lastVerifiedAt": "2024-07-13T02:43:37.640Z",
"verifiedAt": "2024-05-13T04:59:17.640Z",
"isDefault": true,
"webauthnCredential": {
"credentialId": "credential_123",
"deviceId": "device_123",
"name": "iCloud Keychain",
"aaguid": "fbfc3007-154e-4ecc-8c0b-6e020557d7bd",
"aaguidMapping": {
"name": "iCloud Keychain",
"svgIconDark": "data:image/svg+xml;base64...",
"svgIconLight": "data:image/svg+xml;base64..."
},
"credentialBackedUp": true,
"credentialDeviceType": "multiDevice",
"authenticatorAttachment": "platform"
}
}
}{
"error": "<string>",
"errorDescription": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>",
"errorCode": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>"
}Authorizations
Use a short-lived token obtained from the Server API's Track Action endpoint. The token is valid for 10 minutes and should be passed in the Authorization header as 'Bearer {token}'.
Body
The ID of the passkey challenge returned when generating registration options.
The registration credential object, based on https://w3c.github.io/webauthn/#dictdef-registrationresponsejson.
Whether the registration used the automatic passkey upgrade / conditional create flow.
Response
OK
True if the passkey challenge was valid and the device was enrolled successfully.
A new short-term token with scopes to manage authenticators (e.g. add secondary authenticators, remove authenticators, view or regenerate recovery codes). Only present if the challenge succeeded.
The ID of the user's new authenticator which is associated with the passkey credential.
The ID of the Authsignal user associated with the passkey.
Show child attributes
Show child attributes
{
"userAuthenticatorId": "user_authenticator_123",
"verificationMethod": "PASSKEY",
"createdAt": "2024-05-13T04:59:02.640Z",
"lastVerifiedAt": "2024-07-13T02:43:37.640Z",
"verifiedAt": "2024-05-13T04:59:17.640Z",
"isDefault": true,
"webauthnCredential": {
"credentialId": "credential_123",
"deviceId": "device_123",
"name": "iCloud Keychain",
"aaguid": "fbfc3007-154e-4ecc-8c0b-6e020557d7bd",
"aaguidMapping": {
"name": "iCloud Keychain",
"svgIconDark": "data:image/svg+xml;base64...",
"svgIconLight": "data:image/svg+xml;base64..."
},
"credentialBackedUp": true,
"credentialDeviceType": "multiDevice",
"authenticatorAttachment": "platform"
}
}
Was this page helpful?
curl --request POST \
--url https://api.authsignal.com/v1/client/user-authenticators/passkey \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"challengeId": "<string>",
"registrationCredential": {},
"conditionalCreate": true
}
'import requests
url = "https://api.authsignal.com/v1/client/user-authenticators/passkey"
payload = {
"challengeId": "<string>",
"registrationCredential": {},
"conditionalCreate": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({challengeId: '<string>', registrationCredential: {}, conditionalCreate: true})
};
fetch('https://api.authsignal.com/v1/client/user-authenticators/passkey', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.authsignal.com/v1/client/user-authenticators/passkey",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'challengeId' => '<string>',
'registrationCredential' => [
],
'conditionalCreate' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.authsignal.com/v1/client/user-authenticators/passkey"
payload := strings.NewReader("{\n \"challengeId\": \"<string>\",\n \"registrationCredential\": {},\n \"conditionalCreate\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.authsignal.com/v1/client/user-authenticators/passkey")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"challengeId\": \"<string>\",\n \"registrationCredential\": {},\n \"conditionalCreate\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.authsignal.com/v1/client/user-authenticators/passkey")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"challengeId\": \"<string>\",\n \"registrationCredential\": {},\n \"conditionalCreate\": true\n}"
response = http.request(request)
puts response.read_body{
"isVerified": true,
"accessToken": "<string>",
"userAuthenticatorId": "<string>",
"userId": "<string>",
"userAuthenticator": {
"userAuthenticatorId": "user_authenticator_123",
"verificationMethod": "PASSKEY",
"createdAt": "2024-05-13T04:59:02.640Z",
"lastVerifiedAt": "2024-07-13T02:43:37.640Z",
"verifiedAt": "2024-05-13T04:59:17.640Z",
"isDefault": true,
"webauthnCredential": {
"credentialId": "credential_123",
"deviceId": "device_123",
"name": "iCloud Keychain",
"aaguid": "fbfc3007-154e-4ecc-8c0b-6e020557d7bd",
"aaguidMapping": {
"name": "iCloud Keychain",
"svgIconDark": "data:image/svg+xml;base64...",
"svgIconLight": "data:image/svg+xml;base64..."
},
"credentialBackedUp": true,
"credentialDeviceType": "multiDevice",
"authenticatorAttachment": "platform"
}
}
}{
"error": "<string>",
"errorDescription": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>",
"errorCode": "<string>"
}{
"error": "<string>",
"errorDescription": "<string>"
}
