Register a cardholder passkey
POST
/v1/cardholders/{id}/passkeysRequires an API client bearer token.
Verifies the WebAuthn registration response against the single-use challenge minted by the options route, and stores the resulting credential.
Parameters
Path parameters
| Name | Required | Description |
|---|---|---|
| id | required |
Request body
challengeIdstringrequired
originstring (uri)required
responseobjectrequired
+ show properties− hide properties
No properties.
Example
curl -X POST https://api.rigid.fi/v1/cardholders/{id}/passkeys \
-H "Authorization: Bearer $RIGID_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"challengeId": "string",
"origin": "uri",
"response": {}
}'Responses
201The registered credential.
credential_idstringrequired
400Validation error — including a challenge that is invalid, expired, or already consumed
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401Authentication required
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403Forbidden
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404Cardholder not found
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500Internal server error
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring