Skip to content

Register a cardholder passkey

POST/v1/cardholders/{id}/passkeys

Requires an API client bearer token.

Verifies the WebAuthn registration response against the single-use challenge minted by the options route, and stores the resulting credential.

Parameters

Path parameters

NameRequiredDescription
idrequired

Request body

challengeIdstringrequired
originstring (uri)required
responseobjectrequired
+ show properties

No properties.

Example

curl -X POST https://api.rigid.fi/v1/cardholders/{id}/passkeys \
  -H "Authorization: Bearer $RIGID_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "challengeId": "string",
  "origin": "uri",
  "response": {}
}'

Responses

201

The registered credential.

credential_idstringrequired
400

Validation error — including a challenge that is invalid, expired, or already consumed

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401

Authentication required

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403

Forbidden

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404

Cardholder not found

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500

Internal server error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring