> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# List passkeys

> Returns all passkeys registered for an end user, and whether Circle requires SCA for that end user (`sca.required`).




## OpenAPI

````yaml openapi/accounts.yaml get /v1/accounts/passkeys
openapi: 3.1.0
info:
  version: 1.0.0
  title: Accounts (Stablecoin) API
  description: >
    Circle's Accounts API provides endpoints for managing stablecoin accounts --
    including transfers,

    withdrawals, deposits, wire and ACH bank accounts, and blockchain addresses.


    An **Account** is a general representation of a ledger or custody object
    that holds balances. It can be a business account,

    a stablecoin account ledger for an end user, an extra sub-ledger, or any
    future custody solution.
  license:
    name: Circle License
    url: https://circle.com/terms
servers:
  - url: https://api-sandbox.circle.com
  - url: https://api.circle.com
security: []
tags:
  - name: Accounts
    description: Manage accounts.
  - name: Account Groups
    description: Manage custody account groups and their memberships.
  - name: Limits
    description: View effective account limits and current usage.
  - name: Transfers
    description: >
      Move funds between accounts or out to a verified blockchain address, and
      track inbound and outbound onchain transfers.
  - name: Transactions
    description: |
      Get a unified, customer-friendly view of account transaction activity.
  - name: Wires
    description: Manage account bank accounts for wire transfers.
  - name: Deposits
    description: Get information on account bank deposits.
  - name: Withdrawals
    description: Manage account bank withdrawals (fiat offramp).
  - name: ACH
    description: Manage account bank accounts for ACH transfers.
  - name: Deposit Addresses
    description: Manage account deposit addresses.
  - name: Recipient Addresses
    description: Manage account recipient addresses used for transfers.
  - name: Passkeys
    description: >
      Manage WebAuthn passkeys and Strong Customer Authentication (SCA)
      challenges for end users.
  - name: Crypto Payments
    description: >
      Get crypto payments and crypto refunds received through payment intents.
      Available for Digital Asset Accounts only on custody accounts (`purpose:
      custody`), and only for third-party payments. Not supported when the
      distributor or the end user is under the Circle FR (`CIRCLE_FR`) or Circle
      SG (`CIRCLE_SG`) legal entity.
  - name: Crypto Payment Intents
    description: >
      Create, expire, refund, and track payment intents for receiving crypto
      payments. Available for Digital Asset Accounts only on custody accounts
      (`purpose: custody`), and only for third-party payments. Not supported
      when the distributor or the end user is under the Circle FR (`CIRCLE_FR`)
      or Circle SG (`CIRCLE_SG`) legal entity.
  - name: Crypto Payouts
    description: >
      Create and track crypto payouts to recipient addresses. Available for
      Digital Asset Accounts only on custody accounts (`purpose: custody`), and
      only for third-party payouts. Not supported when the distributor or the
      end user is under the Circle FR (`CIRCLE_FR`) or Circle SG (`CIRCLE_SG`)
      legal entity.
  - name: Crypto Address Book
    description: >
      Manage address book recipients used as crypto payout destinations.
      Available for Digital Asset Accounts only on custody accounts (`purpose:
      custody`), and only for third-party payouts. Not supported when the
      distributor or the end user is under the Circle FR (`CIRCLE_FR`) or Circle
      SG (`CIRCLE_SG`) legal entity.
  - name: FX Trades
    description: |
      Quote and execute USDC <> EURC swaps for end users' accounts.
  - name: FX Settlements
    description: Get settlements of FX trades.
  - name: Webhook Subscriptions
    description: Manage subscriptions to Digital Asset Accounts webhook notifications.
  - name: Webhooks
    description: |
      Webhook event payloads Circle sends to a subscribed endpoint.
paths:
  /v1/accounts/passkeys:
    get:
      tags:
        - Passkeys
      summary: List passkeys
      description: >
        Returns all passkeys registered for an end user, and whether Circle
        requires SCA for that end user (`sca.required`).
      operationId: listPasskeys
      parameters:
        - name: clientEntityId
          in: query
          required: true
          description: >
            Identifier of the end user whose passkeys to list. Use the
            `clientEntityId` returned when you create a client with [Create a
            partner
            client](https://developers.circle.com/api-reference/end-user-onboarding/create-partner-client)
            (`POST /v1/partner/clients`).
          schema:
            type: string
            format: uuid
            example: a3f1b2c4-d5e6-7890-abcd-ef1234567890
      responses:
        '200':
          description: Successfully retrieved a list of passkeys.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListPasskeysResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/NotAuthorized'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - bearerAuth: []
components:
  headers:
    XRequestId:
      description: >
        Circle-generated universally unique identifier (UUID v4). Useful for
        identifying a specific request when communicating with Circle Support.
      schema:
        $ref: '#/components/schemas/XRequestId'
  schemas:
    ListPasskeysResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            sca:
              $ref: '#/components/schemas/ScaRequirement'
            passkeys:
              type: array
              description: >
                All passkeys registered for the end user, including revoked ones
                (with `revokedDate` set).
              items:
                $ref: '#/components/schemas/Passkey'
          required:
            - sca
            - passkeys
    XRequestId:
      type: string
      format: uuid
      example: 2adba88e-9d63-44bc-b975-9b6ae3440dde
    ScaRequirement:
      type:
        - object
        - 'null'
      description: >
        Whether Circle requires Strong Customer Authentication (SCA) for this
        end user. Use it to decide whether to prompt passkey enrollment and
        whether to open a challenge before a protected operation. It is a hint:
        the protected endpoint is still the enforcement point, and returns HTTP
        428 when SCA is required and no SCA headers were sent. `null` means
        Circle could not determine whether SCA is required right now; treat it
        as unknown and handle a 428 if one is returned.
      properties:
        required:
          type: boolean
          description: >
            `true` when protected operations acting on this end user's behalf
            require SCA. First-party requests that carry no end user (adding or
            removing a first-party recipient address, first-party wire-account
            creation) never require SCA. `false` means Circle does not require
            SCA; it does not mean SCA is disallowed.
          example: true
      required:
        - required
    Passkey:
      type: object
      properties:
        passkeyId:
          type: string
          format: uuid
          description: Unique identifier for the passkey.
          example: a1b2c3d4-e5f6-7890-ab12-cdef34567890
        credentialId:
          type: string
          description: |
            The WebAuthn credential ID, base64url-encoded.
          example: dGhpcyBpcyBhIGJhc2U2NHVybCBleGFtcGxl
        createDate:
          type: string
          format: date-time
          description: When the passkey was registered.
          example: '2026-09-24T12:00:00Z'
        revokedDate:
          type:
            - string
            - 'null'
          format: date-time
          description: When the passkey was revoked, if applicable.
          example: '2026-09-24T13:00:00Z'
        updateDate:
          type: string
          format: date-time
          description: When the passkey record was last updated.
          example: '2026-09-24T12:01:00Z'
        algorithm:
          type: integer
          description: >
            COSE algorithm identifier for the credential's key pair. `-7` is
            ES256 (P-256), `-257` is RS256.
          example: -7
        aaguid:
          type: string
          description: >
            Authenticator AAGUID in hyphenated UUID format, identifying the
            authenticator model. Self-asserted; not validated.
          example: adce0002-35bc-c60a-648b-0b25f1f05503
        attestationFormat:
          type: string
          description: >
            Attestation format as received from the browser (e.g. `"packed"`,
            `"none"`). Stored verbatim; presence is not evidence of verified
            provenance.
          example: packed
        transports:
          type: array
          items:
            type: string
          description: >
            Transport hints reported by the browser at registration. Fed into
            `allowCredentials` on future ceremonies to guide authenticator
            selection.
          example:
            - internal
            - hybrid
        backupEligible:
          type: boolean
          description: >
            Self-asserted: whether this credential can sync across devices (e.g.
            synced passkeys).
          example: true
        backupState:
          type: boolean
          description: |
            Self-asserted: whether this credential is currently backed up.
          example: true
        signCount:
          type: integer
          format: int64
          description: >
            Signature counter reported by the authenticator. Many synced
            passkeys always report `0` — this alone is not a red flag.
          example: 0
        rpId:
          type: string
          description: >
            The WebAuthn relying-party ID this credential was registered under.
            Recorded per credential to make a future RP-ID migration detectable.
          example: circle.com
        paymentEligible:
          type: boolean
          description: >
            Whether `spcCapable` was requested at enrollment. Records what was
            **requested**, not a verified outcome — `true` means SPC was
            requested, not that the authenticator honored it.
          example: false
      required:
        - passkeyId
        - credentialId
        - createDate
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: integer
          description: >
            Circle internal status code from the platform `CoreStatusCode` enum
            (and its domain-specific extensions). **This is not the HTTP status
            code** — `-1` is the catch-all unknown error, `1`/`2` indicate API
            parameter problems, `3` is forbidden, `4` is unauthorized, and
            larger values identify domain-specific failures. Consumers should
            rely on the HTTP status line for transport-level error class and on
            this field for the specific Circle error case.
          example: 2
        message:
          type: string
          description: >-
            Internal error message; suitable for logging but not for end-user
            display.
          example: API parameter invalid.
        externalMessage:
          type: string
          description: >
            End-user-displayable error message. Present when the server has
            generated a customer-facing variant for this error; omitted
            otherwise.
          example: The provided amount exceeds the maximum allowed.
        errors:
          type: array
          description: Additional request-field validation errors, when available.
          items:
            $ref: '#/components/schemas/ErrorDetail'
    ErrorDetail:
      type: object
      required:
        - error
        - message
      properties:
        error:
          type: string
          description: Machine-readable error identifier.
          example: invalid_value
        location:
          type: string
          description: Query parameter or request field that caused the error.
          example: assetType
        message:
          type: string
          description: Human-readable description of the specific error.
          example: The operation and assetType combination is invalid.
  responses:
    BadRequest:
      description: The request cannot be processed due to a client error.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 2
            message: API parameter invalid.
    NotAuthorized:
      description: >-
        The request has not been applied because it lacks valid authentication
        credentials.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 4
            message: Unauthorized.
    InternalServerError:
      description: >-
        The server encountered an unexpected condition that prevented it from
        fulfilling the request.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: -1
            message: 'Something went wrong. errId: 1f0b0c455e40f753f07b4f0ae6abd4b4'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````