Finish passkey append
curl --request POST \
--url https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"attestationResponse": "{\"type\":\"public-key\",\"id\":\"JM6...J_Q\",\"rawId\":\"JM6...J_Q\",\"authenticatorAttachment\":null,\"response\":{\"clientDataJSON\":\"eyJ...ZX0\",\"authenticatorData\":\"SZY...AAQ\",\"signature\":\"Ni7...YAg\",\"userHandle\":\"dXN...zk5\"},\"clientExtensionResults\":{}}",
"clientInformation": {
"bluetoothAvailable": true,
"clientEnvHandle": "<string>",
"visitorId": "<string>",
"canUsePasskeys": true,
"isUserVerifyingPlatformAuthenticatorAvailable": true,
"isConditionalMediationAvailable": true,
"clientCapabilities": {
"conditionalCreate": true,
"conditionalMediation": true,
"conditionalGet": true,
"hybridTransport": true,
"passkeyPlatformAuthenticator": true,
"userVerifyingPlatformAuthenticator": true,
"relatedOrigins": true,
"signalAllAcceptedCredentials": true,
"signalCurrentUserDetails": true,
"signalUnknownCredential": true
},
"isNative": true,
"webdriver": true,
"privateMode": true
}
}
'import requests
url = "https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish"
payload = {
"attestationResponse": "{\"type\":\"public-key\",\"id\":\"JM6...J_Q\",\"rawId\":\"JM6...J_Q\",\"authenticatorAttachment\":null,\"response\":{\"clientDataJSON\":\"eyJ...ZX0\",\"authenticatorData\":\"SZY...AAQ\",\"signature\":\"Ni7...YAg\",\"userHandle\":\"dXN...zk5\"},\"clientExtensionResults\":{}}",
"clientInformation": {
"bluetoothAvailable": True,
"clientEnvHandle": "<string>",
"visitorId": "<string>",
"canUsePasskeys": True,
"isUserVerifyingPlatformAuthenticatorAvailable": True,
"isConditionalMediationAvailable": True,
"clientCapabilities": {
"conditionalCreate": True,
"conditionalMediation": True,
"conditionalGet": True,
"hybridTransport": True,
"passkeyPlatformAuthenticator": True,
"userVerifyingPlatformAuthenticator": True,
"relatedOrigins": True,
"signalAllAcceptedCredentials": True,
"signalCurrentUserDetails": True,
"signalUnknownCredential": True
},
"isNative": True,
"webdriver": True,
"privateMode": True
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
attestationResponse: '{"type":"public-key","id":"JM6...J_Q","rawId":"JM6...J_Q","authenticatorAttachment":null,"response":{"clientDataJSON":"eyJ...ZX0","authenticatorData":"SZY...AAQ","signature":"Ni7...YAg","userHandle":"dXN...zk5"},"clientExtensionResults":{}}',
clientInformation: {
bluetoothAvailable: true,
clientEnvHandle: '<string>',
visitorId: '<string>',
canUsePasskeys: true,
isUserVerifyingPlatformAuthenticatorAvailable: true,
isConditionalMediationAvailable: true,
clientCapabilities: {
conditionalCreate: true,
conditionalMediation: true,
conditionalGet: true,
hybridTransport: true,
passkeyPlatformAuthenticator: true,
userVerifyingPlatformAuthenticator: true,
relatedOrigins: true,
signalAllAcceptedCredentials: true,
signalCurrentUserDetails: true,
signalUnknownCredential: true
},
isNative: true,
webdriver: true,
privateMode: true
}
})
};
fetch('https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'attestationResponse' => '{"type":"public-key","id":"JM6...J_Q","rawId":"JM6...J_Q","authenticatorAttachment":null,"response":{"clientDataJSON":"eyJ...ZX0","authenticatorData":"SZY...AAQ","signature":"Ni7...YAg","userHandle":"dXN...zk5"},"clientExtensionResults":{}}',
'clientInformation' => [
'bluetoothAvailable' => true,
'clientEnvHandle' => '<string>',
'visitorId' => '<string>',
'canUsePasskeys' => true,
'isUserVerifyingPlatformAuthenticatorAvailable' => true,
'isConditionalMediationAvailable' => true,
'clientCapabilities' => [
'conditionalCreate' => true,
'conditionalMediation' => true,
'conditionalGet' => true,
'hybridTransport' => true,
'passkeyPlatformAuthenticator' => true,
'userVerifyingPlatformAuthenticator' => true,
'relatedOrigins' => true,
'signalAllAcceptedCredentials' => true,
'signalCurrentUserDetails' => true,
'signalUnknownCredential' => true
],
'isNative' => true,
'webdriver' => true,
'privateMode' => true
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish"
payload := strings.NewReader("{\n \"attestationResponse\": \"{\\\"type\\\":\\\"public-key\\\",\\\"id\\\":\\\"JM6...J_Q\\\",\\\"rawId\\\":\\\"JM6...J_Q\\\",\\\"authenticatorAttachment\\\":null,\\\"response\\\":{\\\"clientDataJSON\\\":\\\"eyJ...ZX0\\\",\\\"authenticatorData\\\":\\\"SZY...AAQ\\\",\\\"signature\\\":\\\"Ni7...YAg\\\",\\\"userHandle\\\":\\\"dXN...zk5\\\"},\\\"clientExtensionResults\\\":{}}\",\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"attestationResponse\": \"{\\\"type\\\":\\\"public-key\\\",\\\"id\\\":\\\"JM6...J_Q\\\",\\\"rawId\\\":\\\"JM6...J_Q\\\",\\\"authenticatorAttachment\\\":null,\\\"response\\\":{\\\"clientDataJSON\\\":\\\"eyJ...ZX0\\\",\\\"authenticatorData\\\":\\\"SZY...AAQ\\\",\\\"signature\\\":\\\"Ni7...YAg\\\",\\\"userHandle\\\":\\\"dXN...zk5\\\"},\\\"clientExtensionResults\\\":{}}\",\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"attestationResponse\": \"{\\\"type\\\":\\\"public-key\\\",\\\"id\\\":\\\"JM6...J_Q\\\",\\\"rawId\\\":\\\"JM6...J_Q\\\",\\\"authenticatorAttachment\\\":null,\\\"response\\\":{\\\"clientDataJSON\\\":\\\"eyJ...ZX0\\\",\\\"authenticatorData\\\":\\\"SZY...AAQ\\\",\\\"signature\\\":\\\"Ni7...YAg\\\",\\\"userHandle\\\":\\\"dXN...zk5\\\"},\\\"clientExtensionResults\\\":{}}\",\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}"
response = http.request(request)
puts response.read_bodyUsers
Finish passkey append
Finishes passkey append for currently logged in user.
POST
/
v2
/
me
/
passkeys
/
append
/
finish
Finish passkey append
curl --request POST \
--url https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"attestationResponse": "{\"type\":\"public-key\",\"id\":\"JM6...J_Q\",\"rawId\":\"JM6...J_Q\",\"authenticatorAttachment\":null,\"response\":{\"clientDataJSON\":\"eyJ...ZX0\",\"authenticatorData\":\"SZY...AAQ\",\"signature\":\"Ni7...YAg\",\"userHandle\":\"dXN...zk5\"},\"clientExtensionResults\":{}}",
"clientInformation": {
"bluetoothAvailable": true,
"clientEnvHandle": "<string>",
"visitorId": "<string>",
"canUsePasskeys": true,
"isUserVerifyingPlatformAuthenticatorAvailable": true,
"isConditionalMediationAvailable": true,
"clientCapabilities": {
"conditionalCreate": true,
"conditionalMediation": true,
"conditionalGet": true,
"hybridTransport": true,
"passkeyPlatformAuthenticator": true,
"userVerifyingPlatformAuthenticator": true,
"relatedOrigins": true,
"signalAllAcceptedCredentials": true,
"signalCurrentUserDetails": true,
"signalUnknownCredential": true
},
"isNative": true,
"webdriver": true,
"privateMode": true
}
}
'import requests
url = "https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish"
payload = {
"attestationResponse": "{\"type\":\"public-key\",\"id\":\"JM6...J_Q\",\"rawId\":\"JM6...J_Q\",\"authenticatorAttachment\":null,\"response\":{\"clientDataJSON\":\"eyJ...ZX0\",\"authenticatorData\":\"SZY...AAQ\",\"signature\":\"Ni7...YAg\",\"userHandle\":\"dXN...zk5\"},\"clientExtensionResults\":{}}",
"clientInformation": {
"bluetoothAvailable": True,
"clientEnvHandle": "<string>",
"visitorId": "<string>",
"canUsePasskeys": True,
"isUserVerifyingPlatformAuthenticatorAvailable": True,
"isConditionalMediationAvailable": True,
"clientCapabilities": {
"conditionalCreate": True,
"conditionalMediation": True,
"conditionalGet": True,
"hybridTransport": True,
"passkeyPlatformAuthenticator": True,
"userVerifyingPlatformAuthenticator": True,
"relatedOrigins": True,
"signalAllAcceptedCredentials": True,
"signalCurrentUserDetails": True,
"signalUnknownCredential": True
},
"isNative": True,
"webdriver": True,
"privateMode": True
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
attestationResponse: '{"type":"public-key","id":"JM6...J_Q","rawId":"JM6...J_Q","authenticatorAttachment":null,"response":{"clientDataJSON":"eyJ...ZX0","authenticatorData":"SZY...AAQ","signature":"Ni7...YAg","userHandle":"dXN...zk5"},"clientExtensionResults":{}}',
clientInformation: {
bluetoothAvailable: true,
clientEnvHandle: '<string>',
visitorId: '<string>',
canUsePasskeys: true,
isUserVerifyingPlatformAuthenticatorAvailable: true,
isConditionalMediationAvailable: true,
clientCapabilities: {
conditionalCreate: true,
conditionalMediation: true,
conditionalGet: true,
hybridTransport: true,
passkeyPlatformAuthenticator: true,
userVerifyingPlatformAuthenticator: true,
relatedOrigins: true,
signalAllAcceptedCredentials: true,
signalCurrentUserDetails: true,
signalUnknownCredential: true
},
isNative: true,
webdriver: true,
privateMode: true
}
})
};
fetch('https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'attestationResponse' => '{"type":"public-key","id":"JM6...J_Q","rawId":"JM6...J_Q","authenticatorAttachment":null,"response":{"clientDataJSON":"eyJ...ZX0","authenticatorData":"SZY...AAQ","signature":"Ni7...YAg","userHandle":"dXN...zk5"},"clientExtensionResults":{}}',
'clientInformation' => [
'bluetoothAvailable' => true,
'clientEnvHandle' => '<string>',
'visitorId' => '<string>',
'canUsePasskeys' => true,
'isUserVerifyingPlatformAuthenticatorAvailable' => true,
'isConditionalMediationAvailable' => true,
'clientCapabilities' => [
'conditionalCreate' => true,
'conditionalMediation' => true,
'conditionalGet' => true,
'hybridTransport' => true,
'passkeyPlatformAuthenticator' => true,
'userVerifyingPlatformAuthenticator' => true,
'relatedOrigins' => true,
'signalAllAcceptedCredentials' => true,
'signalCurrentUserDetails' => true,
'signalUnknownCredential' => true
],
'isNative' => true,
'webdriver' => true,
'privateMode' => true
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish"
payload := strings.NewReader("{\n \"attestationResponse\": \"{\\\"type\\\":\\\"public-key\\\",\\\"id\\\":\\\"JM6...J_Q\\\",\\\"rawId\\\":\\\"JM6...J_Q\\\",\\\"authenticatorAttachment\\\":null,\\\"response\\\":{\\\"clientDataJSON\\\":\\\"eyJ...ZX0\\\",\\\"authenticatorData\\\":\\\"SZY...AAQ\\\",\\\"signature\\\":\\\"Ni7...YAg\\\",\\\"userHandle\\\":\\\"dXN...zk5\\\"},\\\"clientExtensionResults\\\":{}}\",\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"attestationResponse\": \"{\\\"type\\\":\\\"public-key\\\",\\\"id\\\":\\\"JM6...J_Q\\\",\\\"rawId\\\":\\\"JM6...J_Q\\\",\\\"authenticatorAttachment\\\":null,\\\"response\\\":{\\\"clientDataJSON\\\":\\\"eyJ...ZX0\\\",\\\"authenticatorData\\\":\\\"SZY...AAQ\\\",\\\"signature\\\":\\\"Ni7...YAg\\\",\\\"userHandle\\\":\\\"dXN...zk5\\\"},\\\"clientExtensionResults\\\":{}}\",\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{projectId}.frontendapi.corbado.io/v2/me/passkeys/append/finish")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"attestationResponse\": \"{\\\"type\\\":\\\"public-key\\\",\\\"id\\\":\\\"JM6...J_Q\\\",\\\"rawId\\\":\\\"JM6...J_Q\\\",\\\"authenticatorAttachment\\\":null,\\\"response\\\":{\\\"clientDataJSON\\\":\\\"eyJ...ZX0\\\",\\\"authenticatorData\\\":\\\"SZY...AAQ\\\",\\\"signature\\\":\\\"Ni7...YAg\\\",\\\"userHandle\\\":\\\"dXN...zk5\\\"},\\\"clientExtensionResults\\\":{}}\",\n \"clientInformation\": {\n \"bluetoothAvailable\": true,\n \"clientEnvHandle\": \"<string>\",\n \"visitorId\": \"<string>\",\n \"canUsePasskeys\": true,\n \"isUserVerifyingPlatformAuthenticatorAvailable\": true,\n \"isConditionalMediationAvailable\": true,\n \"clientCapabilities\": {\n \"conditionalCreate\": true,\n \"conditionalMediation\": true,\n \"conditionalGet\": true,\n \"hybridTransport\": true,\n \"passkeyPlatformAuthenticator\": true,\n \"userVerifyingPlatformAuthenticator\": true,\n \"relatedOrigins\": true,\n \"signalAllAcceptedCredentials\": true,\n \"signalCurrentUserDetails\": true,\n \"signalUnknownCredential\": true\n },\n \"isNative\": true,\n \"webdriver\": true,\n \"privateMode\": true\n }\n}"
response = http.request(request)
puts response.read_bodyAuthorizations
bearerAuthprojectID
After a user logs in successfully, a session is created and a JWT token is returned.
This token represents the user's authenticated session.
It must be included in the Authorization header as a Bearer token for all protected endpoints:
Authorization: Bearer <your-token>
The server will validate this token to authorize access.
Body
application/json
Example:
"{\"type\":\"public-key\",\"id\":\"JM6...J_Q\",\"rawId\":\"JM6...J_Q\",\"authenticatorAttachment\":null,\"response\":{\"clientDataJSON\":\"eyJ...ZX0\",\"authenticatorData\":\"SZY...AAQ\",\"signature\":\"Ni7...YAg\",\"userHandle\":\"dXN...zk5\"},\"clientExtensionResults\":{}}"
Show child attributes
Show child attributes
Response
200
tbd
Was this page helpful?
⌘I