v8
OpenAPI 3.1.02026-08-033623795.0 MBUsers
Delete
Deletes one of the authenticated user's own passkeys. The request body carries a WebAuthn assertion from the passkey being deleted, so possession of the credential is proven before it is removed: mint a deletion challenge for it first, run the ceremony with that passkey, and send the result here. Deleting the user's last passkey is allowed — their other step-up factors remain. Requires a user session.
delete/users/me/passkeys/{id}
Request body
Response
passkey deleted