Register passkey
Profile & security
Register passkey
Session-only. Verify the authenticator’s attestation against the challenge cookie and store the credential. Optionally name the device.
POST
Register passkey
Authorizations
Browser session cookie minted by POST /auth/login (or passkey
login). httpOnly, SameSite=Lax, 24 h TTL. Endpoints marked
Session-only accept only this credential and return
403 session_required for API keys.
Body
application/json