Verify a passkey assertion and sign in.
const url = 'https://api.opdns.io/v1/auth/passkeys/login/finish';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"ceremony_id":"2489E9AD-2EE2-8E00-8EC9-32D5F69181C0","credential":{}}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.opdns.io/v1/auth/passkeys/login/finish \ --header 'Content-Type: application/json' \ --data '{ "ceremony_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "credential": {} }'credential is the PublicKeyCredential from navigator.credentials.get() as
WebAuthn JSON. Sets the opdns_session cookie like password login, with
auth_method passkey. Challenges are single use (replays fail with
ceremony_invalid); a verification failure is 401 invalid_credentials. A
sign counter that did not advance flags the passkey (clone_warning) but
does not fail, because synced passkeys report zero.
Request Bodyrequired
Section titled “Request Bodyrequired”object
object
Examplegenerated
{ "ceremony_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "credential": {}}Responses
Section titled “Responses”Signed in.
object
object
Operator account; may hold the admin scope.
Set while a deletion is pending; the account is erased at this time unless cancelled.
object
A restricted session may only enrol a second factor (TOTP setup/confirm,
passkey registration, GET /v1/auth/me, logout); every other call is 403
mfa_enrolment_required. Set for password-only sign-in after the grace
period, outside dev.
When password-only sign-in becomes restricted; null once a second factor exists, and in dev.
Example
{ "account": { "role": "owner" }, "session": { "auth_method": "password" }}Headers
Section titled “Headers”Malformed request.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/bad_request", "title": "Bad Request", "status": 400, "code": "bad_request", "detail": "invalid JSON body", "request_id": "5f2c9a0e7b1d4c38"}Not authenticated.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/unauthenticated", "title": "Unauthorized", "status": 401, "code": "unauthenticated", "detail": "authentication required", "request_id": "5f2c9a0e7b1d4c38"}Rate limited (rate_limited).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/rate_limited", "title": "Too Many Requests", "status": 429, "code": "rate_limited", "detail": "too many requests", "request_id": "5f2c9a0e7b1d4c38", "retry_after": 6}Headers
Section titled “Headers”Passkeys are not configured on this server (passkeys_unavailable).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/passkeys_unavailable", "title": "Service Unavailable", "status": 503, "code": "passkeys_unavailable", "detail": "passkeys are not configured on this server", "request_id": "5f2c9a0e7b1d4c38"}