Skip to main content
POST
/
v2
/
auth
/
passkey
/
append
/
start
Start passkey append
curl --request POST \
  --url https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start \
  --header 'Authorization: Bearer <token>' \
  --header 'Content-Type: application/json' \
  --data '
{
  "clientInformation": {
    "bluetoothAvailable": true,
    "clientEnvHandle": "<string>",
    "visitorId": "<string>",
    "canUsePasskeys": true,
    "isUserVerifyingPlatformAuthenticatorAvailable": true,
    "isConditionalMediationAvailable": true,
    "clientCapabilities": {
      "conditionalCreate": true,
      "conditionalMediation": true,
      "conditionalGet": true,
      "hybridTransport": true,
      "passkeyPlatformAuthenticator": true,
      "userVerifyingPlatformAuthenticator": true,
      "relatedOrigins": true,
      "signalAllAcceptedCredentials": true,
      "signalCurrentUserDetails": true,
      "signalUnknownCredential": true
    },
    "isNative": true,
    "webdriver": true,
    "privateMode": true
  }
}
'
import requests

url = "https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start"

payload = { "clientInformation": {
"bluetoothAvailable": True,
"clientEnvHandle": "<string>",
"visitorId": "<string>",
"canUsePasskeys": True,
"isUserVerifyingPlatformAuthenticatorAvailable": True,
"isConditionalMediationAvailable": True,
"clientCapabilities": {
"conditionalCreate": True,
"conditionalMediation": True,
"conditionalGet": True,
"hybridTransport": True,
"passkeyPlatformAuthenticator": True,
"userVerifyingPlatformAuthenticator": True,
"relatedOrigins": True,
"signalAllAcceptedCredentials": True,
"signalCurrentUserDetails": True,
"signalUnknownCredential": True
},
"isNative": True,
"webdriver": True,
"privateMode": True
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
clientInformation: {
bluetoothAvailable: true,
clientEnvHandle: '<string>',
visitorId: '<string>',
canUsePasskeys: true,
isUserVerifyingPlatformAuthenticatorAvailable: true,
isConditionalMediationAvailable: true,
clientCapabilities: {
conditionalCreate: true,
conditionalMediation: true,
conditionalGet: true,
hybridTransport: true,
passkeyPlatformAuthenticator: true,
userVerifyingPlatformAuthenticator: true,
relatedOrigins: true,
signalAllAcceptedCredentials: true,
signalCurrentUserDetails: true,
signalUnknownCredential: true
},
isNative: true,
webdriver: true,
privateMode: true
}
})
};

fetch('https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));
<?php

$curl = curl_init();

curl_setopt_array($curl, [
CURLOPT_URL => "https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientInformation' => [
'bluetoothAvailable' => true,
'clientEnvHandle' => '<string>',
'visitorId' => '<string>',
'canUsePasskeys' => true,
'isUserVerifyingPlatformAuthenticatorAvailable' => true,
'isConditionalMediationAvailable' => true,
'clientCapabilities' => [
'conditionalCreate' => true,
'conditionalMediation' => true,
'conditionalGet' => true,
'hybridTransport' => true,
'passkeyPlatformAuthenticator' => true,
'userVerifyingPlatformAuthenticator' => true,
'relatedOrigins' => true,
'signalAllAcceptedCredentials' => true,
'signalCurrentUserDetails' => true,
'signalUnknownCredential' => true
],
'isNative' => true,
'webdriver' => true,
'privateMode' => true
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}
package main

import (
"fmt"
"strings"
"net/http"
"io"
)

func main() {

url := "https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start"

payload := strings.NewReader("{\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}")

req, _ := http.NewRequest("POST", url, payload)

req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")

res, _ := http.DefaultClient.Do(req)

defer res.Body.Close()
body, _ := io.ReadAll(res.Body)

fmt.Println(string(body))

}
HttpResponse<String> response = Unirest.post("https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}")
.asString();
require 'uri'
require 'net/http'

url = URI("https://{projectId}.frontendapi.corbado.io/v2/auth/passkey/append/start")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}"

response = http.request(request)
puts response.read_body
{
  "blockBody": {
    "data": {
      "blockType": "<string>",
      "challenge": "<string>",
      "identifierValue": "<string>",
      "autoSubmit": true
    },
    "alternatives": "<array>",
    "error": {
      "code": "<string>",
      "message": "<string>"
    },
    "continueOnOtherDevice": {}
  },
  "common": {
    "appName": "<string>",
    "frontendApiUrl": "<string>",
    "hideBadge": true,
    "environment": "<string>"
  },
  "newProcess": {
    "token": "<string>",
    "expiresAt": 123
  }
}

Authorizations

Authorization
string
header
required

After a user logs in successfully, a session is created and a JWT token is returned. This token represents the user's authenticated session. It must be included in the Authorization header as a Bearer token for all protected endpoints:

Authorization: Bearer <your-token>

The server will validate this token to authorize access.

Body

application/json
clientInformation
object

Response

200 - application/json

tbd

blockBody
object
required
common
object
required
newProcess
object