---
title: "Provides a challenge for the passkey to authenticate."
method: POST
path: "/v1/users/{userId}/challenges/passkey/verify-start"
tags: ["Accounts"]
---

# Provides a challenge for the passkey to authenticate.

`POST /v1/users/{userId}/challenges/passkey/verify-start`

## Path parameters

- `userId` integer, required

## Request body

- RobloxTwoStepVerificationApiSendCodeRequest — Request parameters for sending a two step verification code.
  - `challengeId` string — The two step verification challenge ID.
  - `actionType` 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 — The Roblox.TwoStepVerification.Client.TwoStepVerificationActionType associated with the challenge. ['Unknown' = 0, 'Login' = 1, 'RobuxSpend' = 2, 'ItemTrade' = 3, 'Resale' = 4, 'PasswordReset' = 5, 'RevertAccount' = 6, 'Generic' = 7, 'GenericWithRecoveryCodes' = 8]

## Response `200`

OK

- RobloxTwoStepVerificationApiVerifyStartPasskeyResponse — Result for a successful verification.
  - `authenticationOptions` string — The authentication options for the passkey.
  - `sessionId` string — The session of the authentication attempt.

## Other responses

- `400` — 1: Invalid challenge ID. 2: The user ID is invalid.
- `403` — 0: Token Validation Failed 8: The user is not allowed to perform the requested action.
- `503` — 7: Two step verification is currently under maintenance.

---

[API](https://skmtc.net/roblox/apis/roblox-api.md) · [All operations](https://skmtc.net/roblox/apis/roblox-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/roblox/roblox-api/versions/e15802062270/schema)
