> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corbado.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a passkey challenge for a user

> Updates a passkey challenge for a user by given `userID` and `passkeyChallengeID`.

Required API key permission: `passkey_challenges:write`.



## OpenAPI

````yaml /api-reference/openapi/connect-backend.yaml patch /users/{userID}/passkeyChallenges/{passkeyChallengeID}
openapi: 3.1.1
info:
  version: 2.0.0
  title: Corbado Backend API
  description: >
    # Introduction

    This documentation gives an overview of all Corbado Backend API calls to
    implement passwordless authentication with Passkeys.
  contact:
    name: Corbado team
    email: support@corbado.com
    url: https://www.corbado.com
servers:
  - url: https://backendapi.cloud.corbado.io/v2
security:
  - basicAuth: []
  - bearerAuth: []
tags:
  - name: ConnectTokens
    description: All API calls to manage connectTokens
    x-group: Connect tokens
  - name: Passkeys
    description: All API calls for passkey flows
    x-group: Passkey ceremonies
  - name: Users
    description: All API calls to manage users
    x-group: Users and passkeys
  - name: Identifiers
    description: All API calls to manage login identifiers
    x-group: Identifiers
  - name: PasskeyEvents
    description: All API calls to manage passkey events
    x-group: Passkey diagnostics
  - name: PasskeyChallenges
    description: All API calls to manage passkey challenges
    x-group: Passkey diagnostics
  - name: Exports
    description: All API calls to manage project export files
    x-group: Data exports
  - name: Connect reads
    description: Connect analytics, process investigation and configuration reads.
    x-group: Analytics and configuration
  - name: ConnectManagement
    description: Connect application and native-app configuration management.
    x-group: App configuration
  - name: ConnectRollout
    description: Connect rollout configuration, rulesets, targeting and simulations.
    x-group: Rollout configuration
  - name: Sessions
    description: All API calls to manage sessions
  - name: Challenges
    description: All API calls to manage challenges
  - name: SSO
    description: All API calls for SSO flows
  - name: AuthEvents
    description: All API calls to manage authentication events
  - name: ProjectConfig
    description: All API calls to manage project configurations
  - name: WebhookEndpoints
    description: All API calls to manage webhook endpoints
  - name: PasswordManagers
    description: All API calls to manage password managers
  - name: ClientEnvs
    description: All API calls to manage client environments
  - name: Devices
    description: All API calls to manage devices
paths:
  /users/{userID}/passkeyChallenges/{passkeyChallengeID}:
    patch:
      tags:
        - PasskeyChallenges
      summary: Update a passkey challenge for a user
      description: >-
        Updates a passkey challenge for a user by given `userID` and
        `passkeyChallengeID`.


        Required API key permission: `passkey_challenges:write`.
      operationId: PasskeyChallengeUpdate
      parameters:
        - $ref: '#/components/parameters/userID'
        - $ref: '#/components/parameters/passkeyChallengeID'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/passkeyChallengeUpdateReq'
      responses:
        '200':
          description: Passkey challenge has been updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/passkeyChallenge'
        default:
          $ref: '#/components/responses/error'
      security:
        - basicAuth: []
        - bearerAuth:
            - passkey_challenges:write
components:
  parameters:
    userID:
      name: userID
      in: path
      description: |
        Unique identifier of the user. Format: `usr-<number>`.
      required: true
      schema:
        type: string
        example: usr-4693224802260150919
    passkeyChallengeID:
      name: passkeyChallengeID
      in: path
      description: ID of a passkey challenge
      required: true
      schema:
        type: string
  schemas:
    passkeyChallengeUpdateReq:
      type: object
      required:
        - status
      properties:
        status:
          $ref: '#/components/schemas/passkeyChallengeStatus'
    passkeyChallenge:
      type: object
      required:
        - challengeID
        - type
        - value
        - status
        - created
        - createdMs
        - expires
      properties:
        challengeID:
          type: string
        type:
          $ref: '#/components/schemas/passkeyChallengeType'
        value:
          type: string
        status:
          $ref: '#/components/schemas/passkeyChallengeStatus'
        created:
          type: integer
          format: int64
        createdMs:
          type: integer
          format: int64
        expires:
          type: integer
          format: int64
    passkeyChallengeStatus:
      type: string
      enum:
        - pending
        - completed
        - consumed
    passkeyChallengeType:
      type: string
      enum:
        - register
        - authenticate
  responses:
    error:
      description: Error
      content:
        application/json:
          schema:
            allOf:
              - type: object
                required:
                  - httpStatusCode
                  - message
                  - requestData
                  - runtime
                properties:
                  httpStatusCode:
                    description: HTTP status code of operation
                    type: integer
                    format: int32
                  message:
                    type: string
                    example: OK
                  requestData:
                    description: Data about the request itself, can be used for debugging
                    type: object
                    required:
                      - requestID
                    properties:
                      requestID:
                        description: >-
                          Unique ID of request, you can provide your own while
                          making the request, if not the ID will be randomly
                          generated on server side
                        type: string
                        example: req-557...663
                      link:
                        description: Link to dashboard with details about request
                        type: string
                        example: >-
                          https://my.corbado.com/requests/req-xxxxxxxxxxxxxxxxxxx
                  runtime:
                    description: Runtime in seconds for this request
                    type: number
                    format: float
                    example: 0.06167686
              - type: object
                required:
                  - error
                properties:
                  data:
                    type: object
                  error:
                    type: object
                    required:
                      - type
                    properties:
                      type:
                        description: Type of error
                        type: string
                      details:
                        description: Details of error
                        type: string
                      validation:
                        description: Validation errors per field
                        type: array
                        items:
                          type: object
                          required:
                            - field
                            - message
                          properties:
                            field:
                              type: string
                            message:
                              type: string
                      links:
                        description: Additional links to help understand the error
                        type: array
                        items:
                          type: string
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: >
        Basic authentication is used to authenticate requests to the Backend
        API. The username is the project ID and the password is the API secret.


        The project ID and API secret can be found in the [Management
        Console](https://app.corbado.com/settings/api-secrets).
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Use your versioned Backend API key. The key must grant the operation
        permission and satisfy its expiry and IP restrictions.

````