curl --request GET \
--url https://api.cloud.corbado.io/v1/observe/metadata/mds \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.cloud.corbado.io/v1/observe/metadata/mds"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.cloud.corbado.io/v1/observe/metadata/mds', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cloud.corbado.io/v1/observe/metadata/mds",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.cloud.corbado.io/v1/observe/metadata/mds"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.cloud.corbado.io/v1/observe/metadata/mds")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cloud.corbado.io/v1/observe/metadata/mds")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"identifier": "<string>",
"identifierType": "aaguid",
"name": "<string>",
"protocolFamily": "<string>",
"latestStatus": "<string>",
"metadataStatement": {},
"statusReports": [
{}
],
"blobNo": 123,
"aaguid": "<string>",
"aaid": "<string>",
"certKeyIds": [
"<string>"
],
"timeOfLastStatusChange": "<string>",
"icon": "<string>",
"iconDark": "<string>"
}
]{
"error": {
"message": "Validation failed",
"details": [
{
"field": "projectID",
"message": "required"
}
]
}
}List FIDO MDS authenticator metadata
Returns FIDO Metadata Service (MDS) authenticator entries. Pass a comma-separated list of FIDO2 AAGUIDs to look up specific authenticators (AAGUIDs with no matching entry are omitted from the response), or omit the aaguids parameter to return the full catalog. Use this to display authenticator details (name, icon, transports, certification status) for passkey credentials, e.g. YubiKeys. This is global reference data and is not project-scoped.
Required API key permission: observe:metadata:read.
curl --request GET \
--url https://api.cloud.corbado.io/v1/observe/metadata/mds \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.cloud.corbado.io/v1/observe/metadata/mds"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.cloud.corbado.io/v1/observe/metadata/mds', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cloud.corbado.io/v1/observe/metadata/mds",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.cloud.corbado.io/v1/observe/metadata/mds"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.cloud.corbado.io/v1/observe/metadata/mds")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cloud.corbado.io/v1/observe/metadata/mds")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"identifier": "<string>",
"identifierType": "aaguid",
"name": "<string>",
"protocolFamily": "<string>",
"latestStatus": "<string>",
"metadataStatement": {},
"statusReports": [
{}
],
"blobNo": 123,
"aaguid": "<string>",
"aaid": "<string>",
"certKeyIds": [
"<string>"
],
"timeOfLastStatusChange": "<string>",
"icon": "<string>",
"iconDark": "<string>"
}
]{
"error": {
"message": "Validation failed",
"details": [
{
"field": "projectID",
"message": "required"
}
]
}
}Authorizations
Use an Observe API key from the management console. The key selects the project and must grant the permission listed on the operation. Keep this key on your server.
Query Parameters
Optional comma-separated authenticator AAGUIDs (UUID format) to look up. If omitted, all entries are returned.
Response
FIDO MDS authenticator metadata entries.
Canonical key for this entry (aaguid, aaid, or a u2f cert-key-id derived value).
Which identifier family keys this entry.
aaguid, aaid, u2f Human-readable authenticator description, e.g. "YubiKey 5 Series with NFC".
FIDO protocol family, e.g. fido2, u2f or uaf.
Most recent certification status, e.g. FIDO_CERTIFIED_L1 or NOT_FIDO_CERTIFIED.
Full FIDO MDS metadata statement JSON (icons extracted into the icon fields).
Full FIDO MDS certification status report history.
Sequence number of the source MDS BLOB this entry was imported from.
Authenticator AAGUID (present for FIDO2 authenticators).
Authenticator AAID (present for FIDO UAF authenticators).
Attestation certificate key identifiers (present for FIDO U2F authenticators).
Date of the last certification status change (YYYY-MM-DD).
Light-mode authenticator icon as a base64 PNG data URI.
Dark-mode authenticator icon as a base64 PNG data URI.
Was this page helpful?