Skip to main content
POST
Open a passkey registration session

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
clientEntityId
string
required

The end-user identifier to enroll.

Example:

"entity_01234567890abcdef"

idempotencyKey
string<uuid>
required

A unique key for this registration session. Replaying the same key for the same clientEntityId, spcCapable, and embedOrigin returns the original session unchanged. Using the same key for a different clientEntityId, spcCapable, or embedOrigin value returns 409. Omitting embedOrigin on a replay is not a conflict.

Example:

"550e8400-e29b-41d4-a716-446655440000"

spcCapable
boolean
default:false

Whether this credential should be marked as eligible for Secure Payment Confirmation (SPC). Defaults to false. This flag is recorded permanently at enrollment and cannot be changed later.

embedOrigin
string

The origin of your page that embeds the passkey enrollment ceremony, for example https://app.example.com. It must exactly match one of the origins approved for your account (scheme, host, and port; no trailing slash or path). Send it on every call. It is required when more than one origin is approved for your account: without it, the request fails with 400. When only one origin is approved, omitting it uses that origin. A blank value, or one that matches none of your approved origins, also fails with 400. The passkey enrollment ceremony is bound to this origin: when it is embedded, it can only be completed inside a page on this origin, and it posts its result only to this origin. If this origin is removed from your approved origins before enrollment completes, the enrollment fails.

Required string length: 1 - 512
Example:

"https://app.example.com"

Response

Successfully opened a passkey registration session.

data
object