SECURITY_SETUP_REQUIRED challenge instead of tokens:
confirming a sign-up,
an email-verified password login,
changing a temporary password,
and finishing a password reset.
session_token from the challenge is what you send on
every call below. None of them take a bearer token, because there isn’t one yet.
The flow
Pick one path, then finish. Three calls for a passkey, three for 2FA.Passkey path (recommended)
- Set up a passkey (start): send the
session_token. You get backpublicKeycreation options. - Create the passkey on the device. Pass those options to
navigator.credentials.create()on the web, or the platform credential API on iOS and Android. The OS asks the user for Face ID, Touch ID, or their screen lock and returns an attestation. - Set up a passkey (finish): send the
session_tokenand the attestation. The passkey is now stored.
2FA path
- Set up 2FA (start): send the
session_token. You get back asecretand anotpauth://qr_uri. Render the QR code so the user can scan it into their authenticator app. - Set up 2FA (confirm): send the
session_tokenand the first 6-digit code the app shows. 2FA is now on.
Finish and get tokens
Whichever path you took, call Finish security setup with thesession_token. It returns the full set of
tokens and the user is signed in.
The
session_token is short-lived. If it expires you get 410 SESSION_EXPIRED. Send the
user back through the flow that issued it (log in again, for example) to get a fresh one.