Finalize WebAuthn login
curl --request POST \
--url https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize \
--header 'Authorization: Bearer <token>' \
--header 'X-Authorization: <api-key>'import requests
url = "https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize"
headers = {
"Authorization": "Bearer <token>",
"X-Authorization": "<api-key>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'X-Authorization': '<api-key>'}
};
fetch('https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize")
.header("Authorization", "Bearer <token>")
.header("X-Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"access": "<string>",
"refresh": "<string>",
"csrf": "<string>",
"access_expires_at": "2023-11-07T05:31:56Z",
"refresh_expires_at": "2023-11-07T05:31:56Z",
"user_id": "<string>",
"key_id": "<string>",
"credential_id": "<string>"
}{
"error": "User not found"
}{
"error": "Webauthn error"
}WebAuthn
Finalize WebAuthn login
Finalize a WebAuthn authentication ceremony by verifying the credential assertion from the browser. Returns session tokens upon successful verification. Use the SDK instead of calling this manually.
POST
/
v1
/
auth
/
{app_id}
/
webauthn
/
login
/
finalize
Finalize WebAuthn login
curl --request POST \
--url https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize \
--header 'Authorization: Bearer <token>' \
--header 'X-Authorization: <api-key>'import requests
url = "https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize"
headers = {
"Authorization": "Bearer <token>",
"X-Authorization": "<api-key>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'X-Authorization': '<api-key>'}
};
fetch('https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-Authorization: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-Authorization", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize")
.header("Authorization", "Bearer <token>")
.header("X-Authorization", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{defaultHost}/v1/auth/{app_id}/webauthn/login/finalize")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Authorization"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"access": "<string>",
"refresh": "<string>",
"csrf": "<string>",
"access_expires_at": "2023-11-07T05:31:56Z",
"refresh_expires_at": "2023-11-07T05:31:56Z",
"user_id": "<string>",
"key_id": "<string>",
"credential_id": "<string>"
}{
"error": "User not found"
}{
"error": "Webauthn error"
}Authorizations
API Secret token
User Access token
Path Parameters
App ID
Response
authentication successful
JWT access token
JWT refresh token
CSRF token for protected operations
Access token expiration timestamp
Refresh token expiration timestamp
App user ID
App key ID for JWT verification
WebAuthn credential ID
Was this page helpful?
⌘I