v1

latestOpenAPI 3.1.02026-07-268342124.0 KB
users

Enroll verified authenticator

Enroll an authenticator on behalf of a user. This operation should only be used in cases where you have already verified a user's email address or phone number in your own system.

post/users/{userId}/authenticators

Path parameters

userIdstring required

The ID of the user.

Request body

verificationMethod'EMAIL_MAGIC_LINK' | 'EMAIL_OTP' | 'SMS' | 'AUTHENTICATOR_APP' | 'PASSKEY' | 'WHATSAPP' required

The verification method of the authenticator being enrolled.

emailstring

The user's email address. Required for EMAIL_MAGIC_LINK and EMAIL_OTP.

phoneNumberstring

The user's phone number in E.164 format. Required for SMS.

otpUristring

The formatted OTP URI. Required for AUTHENTICATOR_APP.

oobChannel'EMAIL_MAGIC_LINK' | 'EMAIL_OTP' | 'SMS'

Deprecated - use 'verificationMethod' instead.

credentialIdstring

The passkey credential ID from the WebAuthn credential. Required for PASSKEY.

credentialPublicKeystring

The passkey credential public key (base64url-encoded). Required for PASSKEY.

counternumber

The signature counter from the WebAuthn authenticator. Used for PASSKEY to detect cloned credentials.

namestring

A display name for the passkey authenticator (e.g. device or browser name). Used for PASSKEY.

usernamestring

The WebAuthn username associated with the passkey (e.g. the user's email or handle shown in the browser's passkey picker). Used for PASSKEY.

transportsstring[]

Transport hints for the passkey (e.g. "internal", "hybrid"). Used for PASSKEY.

aaguidstring

The AAGUID of the authenticator that created the passkey. Used for PASSKEY.

isDefaultboolean

Whether this authenticator should be set as the user's default.

Response

OK

recoveryCodesstring[]

Example response

{
  "authenticator": {
    "userAuthenticatorId": "4efd2d0d-3278-4e03-8143-d9a0850bebc0",
    "verificationMethod": "PASSKEY",
    "username": "jane.smith@authsignal.com",
    "displayName": "Jane Smith",
    "createdAt": "2024-05-13T04:59:02.640Z",
    "lastVerifiedAt": "2024-07-13T02:43:37.640Z",
    "verifiedAt": "2024-05-13T04:59:17.640Z",
    "webauthnCredential": {
      "credentialId": "71273a99-4a7b-47d4-82ab-9ea72b8f0a72",
      "deviceId": "d5a13d2d-8c34-4c90-938b-d8c6e3a88c5d",
      "name": "iCloud Keychain",
      "aaguid": "fbfc3007-154e-4ecc-8c0b-6e020557d7bd",
      "aaguidMapping": {
        "name": "iCloud Keychain",
        "svgIconDark": "data:image/svg+xml;base64...",
        "svgIconLight": "data:image/svg+xml;base64..."
      },
      "credentialBackedUp": true,
      "credentialDeviceType": "multiDevice",
      "authenticatorAttachment": "platform"
    }
  }
}