Which operations need it
For secure card details, use the
POST form above. It’s the only one that can carry a
passkey confirmation. On an SSO session the legacy GET form is refused.The flow
Step 1: enrol the user (once per device)
An SSO user registers a passkey with the ordinary add-a-passkey endpoints, authenticated with the token they already hold. One extra step applies only to SSO: the user confirms a code emailed to them before the passkey challenge is issued.1
Start. A code is emailed.
Start adding a passkey
with
Authorization: Bearer <access_token> and an optional friendly_name (for example
"My iPhone"). On an SSO program this doesn’t return publicKey yet. It emails the
user a verification code and responds with:2
Start again, with the code.
Collect the code from the user and call the same endpoint again, same body plus
Once the code checks out you get the normal response, a
email_code:session_token and publicKey
creation options, and continue as any other program would.3
On the device
Pass
publicKey to navigator.credentials.create() on the web, or the platform
credential API on iOS and Android. The OS asks the user for Face ID, Touch ID, or
their screen lock.4
Finish
Finish adding a passkey
with the
session_token and the attestation the device produced.The code goes to the email on the user’s Orenda account. If your identity provider changes
a user’s email, the code still goes to the address we hold, not the new one.
Step 2: get a challenge
Right before the sensitive call, request a step-up passkey challenge:Step 3: unlock on the device
Convert the base64url fields to byte arrays, callnavigator.credentials.get() (or the
native equivalent), and encode the result back to base64url. The
mechanics are the same as passkey login.
Step 4: send the confirmation
Add aconfirmation object to the operation’s request body:
confirmation shape every other step-up in the API uses. See
Confirming a sensitive action.
Errors
Both are422, with the code in the response body:
The
SCA_MISSING message names the accepted method: "Authentication is required (passkey)" on an SSO session, versus "Authentication is required (passkey, TOTP, or PIN)" elsewhere. Branch on the code, not the message text.Building for it
1
Ship enrolment with your first release
Add a passkey screen and prompt existing users. Without enrolled users, payees,
international payments, batches, invites, and card details are all unreachable.
2
Handle 422 as a prompt, not a failure
Treat
SCA_MISSING as “ask the user to confirm”, run the challenge, and retry the same
call. Don’t show it as an error.3
Check device support
Passkeys need WebAuthn. Detect support before you offer it
(
PublicKeyCredential.isUserVerifyingPlatformAuthenticatorAvailable()) and tell users
which of their devices can enrol.4
Ask us if you get stuck
Contact the team if enrolment or step-up doesn’t
behave as described here.