Skip to content
Esc
navigateopen⌘Jpreview
Dashboard

Generate authentication options

Generate the webauthn options for signin.

POST/appid-{appId}/{tenantId}/recipe/webauthn/options/signin
Authorization
api-keyAPI key · headerrequired
The core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Path parameters
tenantIdstring
The tenant against which the request is made. If left empty, the default tenant will be used.
Header parameters
cdi-versionstring
X.Y of the X.Y.Z CDI version.
Request body
application/json
relyingPartyIdstringrequired
relyingPartyNamestringrequired
originstringrequired
timeoutnumberrequired
userVerificationstringrequired
userPresencebooleanrequired
Responses
200AuthRecipeUser for the token
One of:
object
statusstatusOK
Allowed:OK
webauthnGeneratedOptionsIdstring
relyingPartyIdstring
challengestring
timeoutnumber
userVerificationstring
userPresenceboolean
createdAtnumber
expiresAtnumber
object
statusstring
Allowed:INVALID_OPTIONS_ERROR
reasonstring
400error code 400
string
401error code 401
string
404error code 404
string
500error code 500
string
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/public/recipe/webauthn/options/signin" \
  -H "api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "relyingPartyId": "example.com",
  "relyingPartyName": "Example",
  "origin": "http://example.com",
  "timeout": 10000,
  "userVerification": "preferred",
  "userPresence": false
}'
Response
{
  "status": "OK",
  "webauthnGeneratedOptionsId": "fa7a0841-b533-4478-9253-0fde890c576",
  "relyingPartyId": "example.com",
  "challenge": "TQvEVDV8B64w_2zIifzKaPzBPfthqpx2uJkq_2PIB0k",
  "timeout": 10000,
  "userVerification": "required",
  "userPresence": true,
  "createdAt": 1741793746,
  "expiresAt": 1741793746
}

API reference

API schema and response details