> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# DAA web SDK reference

> SDK reference for the DAA web SDK package, which runs the Strong Customer Authentication ceremony in your web application.

The DAA web SDK handles the client-side Strong Customer Authentication (SCA)
ceremony for Digital Asset Accounts. Your backend creates a frame token through
the Circle API; the SDK uses that token to render the WebAuthn passkey prompt in
a Circle-hosted iframe and return the signed result.

For a step-by-step integration guide, see
[How-to: Implement Strong Customer Authentication](/digital-asset-accounts/howtos/strong-customer-authentication).

## Install

```shell theme={null}
npm install @circle-fin/daa-web-sdk
```

## `createScaClient`

Creates an SCA client bound to the given environment.

```typescript theme={null}
import { createScaClient } from "@circle-fin/daa-web-sdk";

const sca = createScaClient({ environment: "sandbox" });
```

### Parameters

| Parameter | Type | Required | Description |
| - | - | - | - |
| `options.environment` | `"sandbox" \| "production"` | Yes | Determines which Circle-hosted iframe origin to load. |

### Returns

An `ScaClient` instance with `enroll` and `approve` methods.

***

## `sca.enroll`

Runs the passkey enrollment ceremony. Call this once per end user per device,
using the frame token from `POST /v1/accounts/passkeys/registrations`.

```typescript theme={null}
const attestationResponse = await sca.enroll(frameToken, { mode: "modal" });
```

### Parameters

| Parameter | Type | Required | Description |
| - | - | - | - |
| `frameToken` | `string` | Yes | Opaque token returned by `POST /v1/accounts/passkeys/registrations`. |
| `presentation.mode` | `"modal" \| "inline"` | Yes | `"modal"` renders the ceremony in an overlay. `"inline"` renders it inside a container element you provide. |
| `presentation.container` | `unknown` | Yes (inline only) | The container element to mount the ceremony into. Required when `mode` is `"inline"`. |
| `options.signal` | `AbortSignal` | No | Cancels the ceremony when aborted. The promise rejects with `code: 'Cancelled'`. |

### Returns

`attestationResponse`: a structured object representing the signed WebAuthn
attestation. Pass it to your backend and forward it to
`POST /v1/accounts/passkeys` unchanged.

<Warning>
  Do not re-serialize `attestationResponse` before forwarding it to your
  backend. Re-serialization alters the binary encoding and causes a verification
  error.
</Warning>

***

## `sca.approve`

Runs the operation approval ceremony. Call this for every protected operation,
using the frame token from `POST /v1/accounts/passkeys/challenges`.

```typescript theme={null}
const assertion = await sca.approve(frameToken, { mode: "modal" });
```

### Parameters

| Parameter | Type | Required | Description |
| - | - | - | - |
| `frameToken` | `string` | Yes | Opaque token returned by `POST /v1/accounts/passkeys/challenges`. |
| `presentation.mode` | `"modal" \| "inline"` | Yes | `"modal"` renders the ceremony in an overlay. `"inline"` renders it inside a container element you provide. |
| `presentation.container` | `unknown` | Yes (inline only) | The container element to mount the ceremony into. Required when `mode` is `"inline"`. |
| `options.signal` | `AbortSignal` | No | Cancels the ceremony when aborted. The promise rejects with `code: 'Cancelled'`. |

### Returns

`assertion`: a string. Pass it to your backend and include it as the
`X-Sca-Assertion` header on the protected API request.

***

## Error handling

Both `enroll` and `approve` throw if the ceremony fails or the frame token is
invalid. Wrap calls in `try/catch` and surface errors to the end user.

```typescript theme={null}
try {
  const assertion = await sca.approve(frameToken, { mode: "modal" });
} catch (err) {
  // Show an error state and allow the user to retry
}
```

Common failure causes:

| DAA error code | Numeric code | Cause | What to do |
| - | - | - | - |
| `CEREMONY_CONSUMED_OR_EXPIRED` | 420057 | Frame token already used or expired (10 min enrollment / 5 min challenge). | Fetch a new token from your backend and retry. |
| `CEREMONY_TOKEN_REQUIRED` | 420056 | Frame token missing or malformed. | Ensure you pass the `frameToken` exactly as returned by the backend. |
| `SCA_ORIGIN_NOT_CONFIGURED` | 420064 | Your application origin is not registered. | Contact your support team to register the origin before running any ceremony. |
| `Cancelled` | — | User dismissed the ceremony or a cancel signal fired. | Prompt the user to try again, or handle the cancellation gracefully. |
