Skip to content
Esc
navigateopen⌘Jpreview
Dashboard

Generate registration options

Generate the webauthn options for registration.

POST/appid-{appId}/{tenantId}/recipe/webauthn/options/register
Authorization
api-keyAPI key · headerrequired
The core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Path parameters
tenantIdstring
The tenant against which the request is made. If left empty, the default tenant will be used.
Header parameters
cdi-versionstring
X.Y of the X.Y.Z CDI version.
Request body
application/json
emailemailrequired
displayNamestring
relyingPartyIdstringrequired
relyingPartyNamestringrequired
originstringrequired
timeoutnumber
userVerificationstring
userPresenceboolean
attestationstring
residentKeystring
supportedAlgorithmIDsnumber[]
Responses
200The generated register options response
One of:
object
statusstatusOK
Allowed:OK
webauthnGeneratedOptionsIdstring
rpobject
Show properties
idstring
namestring
userobject
Show properties
idstring
namestring
displayNamestring
emailemail
challengestring
timeoutnumber
attestationstring
createdAtnumber
expiresAtnumber
pubKeyCredParamsobject[]
Show properties
Array of object
typestring
algnumber
excludeCredentialsobject[]
Show properties
Array of object
idstring
transportstring[]
authenticatorSelectionobject
Show properties
userVerificationstring
requireResidentKeyboolean
object
statusstring
Allowed:INVALID_OPTIONS_ERROR
reasonstring
400error code 400
string
401error code 401
string
404error code 404
string
500error code 500
string
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/public/recipe/webauthn/options/register" \
  -H "api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "email": "[email protected]",
  "displayName": "John Doe",
  "relyingPartyId": "example.com",
  "relyingPartyName": "Example",
  "origin": "http://example.com",
  "timeout": 10000,
  "userVerification": "preferred",
  "userPresence": false,
  "attestation": "none",
  "residentKey": "required",
  "supportedAlgorithmIDs": [
    -7
  ]
}'
Response
{
  "status": "OK",
  "webauthnGeneratedOptionsId": "fa7a0841-b533-4478-9253-0fde890c576",
  "rp": {
    "id": "example.com",
    "name": "Example"
  },
  "user": {
    "id": "fa7a0841-b533-4478-9253-0fde890c576",
    "name": "John Doe",
    "displayName": "John Doe"
  },
  "email": "[email protected]",
  "challenge": "TQvEVDV8B64w_2zIifzKaPzBPfthqpx2uJkq_2PIB0k",
  "timeout": 10000,
  "attestation": "none",
  "createdAt": 1741793746,
  "expiresAt": 1741793746,
  "pubKeyCredParams": [
    {
      "type": "public-key",
      "alg": -7
    }
  ],
  "excludeCredentials": [
    {
      "id": "fa7a0841-b533-4478-9253-0fde890c576",
      "transport": [
        "internal"
      ]
    }
  ],
  "authenticatorSelection": {
    "userVerification": "preferred",
    "requireResidentKey": true
  }
}

API reference

API schema and response details