Verify signedPasskeyData from a passkey login
curl --request POST \
--url https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"signedPasskeyData": "<string>",
"username": "<string>"
}
'import requests
url = "https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData"
payload = {
"signedPasskeyData": "<string>",
"username": "<string>"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({signedPasskeyData: '<string>', username: '<string>'})
};
fetch('https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'signedPasskeyData' => '<string>',
'username' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData"
payload := strings.NewReader("{\n \"signedPasskeyData\": \"<string>\",\n \"username\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"signedPasskeyData\": \"<string>\",\n \"username\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"signedPasskeyData\": \"<string>\",\n \"username\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"verificationResult": "success"
}{
"httpStatusCode": 123,
"message": "OK",
"requestData": {
"requestID": "req-557...663",
"link": "https://my.corbado.com/requests/req-xxxxxxxxxxxxxxxxxxx"
},
"runtime": 0.06167686,
"error": {
"type": "<string>",
"details": "<string>",
"validation": [
{
"field": "<string>",
"message": "<string>"
}
],
"links": [
"<string>"
]
},
"data": {}
}Passkey ceremonies
Verify signedPasskeyData from a passkey login
Verifies signedPasskeyData returned by Connect login finish.
Set username to the expected WebAuthn identifier. Create an application session only when the
HTTP request succeeds and verificationResult is success; decoding a JWT alone does not verify it.
See signed passkey data and the backend integration guide.
Required API key permission: passkeys:verify.
POST
/
passkey
/
verifySignedData
Verify signedPasskeyData from a passkey login
curl --request POST \
--url https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"signedPasskeyData": "<string>",
"username": "<string>"
}
'import requests
url = "https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData"
payload = {
"signedPasskeyData": "<string>",
"username": "<string>"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({signedPasskeyData: '<string>', username: '<string>'})
};
fetch('https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'signedPasskeyData' => '<string>',
'username' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData"
payload := strings.NewReader("{\n \"signedPasskeyData\": \"<string>\",\n \"username\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"signedPasskeyData\": \"<string>\",\n \"username\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://backendapi.cloud.corbado.io/v2/passkey/verifySignedData")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"signedPasskeyData\": \"<string>\",\n \"username\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"verificationResult": "success"
}{
"httpStatusCode": 123,
"message": "OK",
"requestData": {
"requestID": "req-557...663",
"link": "https://my.corbado.com/requests/req-xxxxxxxxxxxxxxxxxxx"
},
"runtime": 0.06167686,
"error": {
"type": "<string>",
"details": "<string>",
"validation": [
{
"field": "<string>",
"message": "<string>"
}
],
"links": [
"<string>"
]
},
"data": {}
}Authorizations
basicAuthbearerAuth
Basic authentication is used to authenticate requests to the Backend API. The username is the project ID and the password is the API secret.
The project ID and API secret can be found in the Management Console.
Response
signedPasskeyData has been verified.
Available options:
success, invalid_signature, invalid_challenge, user_mismatch, generic_error Was this page helpful?