Start registering a passkey (session only, step-up).
const url = 'https://api.opdns.io/v1/auth/passkeys/register/begin';const options = {method: 'POST', headers: {cookie: 'opdns_session=<opdns_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.opdns.io/v1/auth/passkeys/register/begin \ --cookie opdns_session=<opdns_session>Returns a ceremony id and the options to pass to navigator.credentials.create()
(options.publicKey, base64url-encoded binary fields as in WebAuthn JSON).
Discoverable credentials are preferred, attestation is none, the account’s
existing passkeys are excluded. The challenge expires after five minutes and is
single use. Allowed for a restricted session.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”Creation options.
object
Echo it to the matching /finish call.
WebAuthn CredentialCreationOptions / CredentialRequestOptions JSON:
pass options.publicKey through PublicKeyCredential.parseCreationOptionsFromJSON
(or parseRequestOptionsFromJSON); binary fields are base64url.
object
object
Examplegenerated
{ "ceremony_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "options": { "publicKey": {}, "mediation": "example" }}Not authenticated.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/unauthenticated", "title": "Unauthorized", "status": 401, "code": "unauthenticated", "detail": "authentication required", "request_id": "5f2c9a0e7b1d4c38"}Authenticated but not allowed: insufficient_scope, session_required, csrf_rejected, mfa_enrolment_required (restricted session), mfa_required (an operator action, or an admin-scoped token, from a session signed in with the password alone; not in dev), reauth_required (sign in again within five minutes), account_pending_deletion (the account is in its deletion cooling-off).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/insufficient_scope", "title": "Forbidden", "status": 403, "code": "insufficient_scope", "detail": "the token lacks the profiles:write scope", "request_id": "5f2c9a0e7b1d4c38"}Passkeys are not configured on this server (passkeys_unavailable).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/passkeys_unavailable", "title": "Service Unavailable", "status": 503, "code": "passkeys_unavailable", "detail": "passkeys are not configured on this server", "request_id": "5f2c9a0e7b1d4c38"}