Skip to main content
Provides 2 public methods:
  • signup — Register a new user with a passkey (full flow: challenge → WebAuthn → token exchange)
  • login — Sign in with a passkey (full flow: challenge → WebAuthn → token exchange)

Methods

getLoginChallenge()

Request a passkey login challenge. Step 1 of the granular login flow. Returns the auth session and a decoded PublicKeyCredentialRequestOptions. Run the WebAuthn assertion ceremony with publicKey, then hand the resulting credential and authSession to getTokenWithPasskey().

Parameters

PasskeyLoginChallengeOptions
Optional login challenge options (realm/organization)Type: PasskeyLoginChallengeOptions

Returns

Promise<PasskeyLoginChallenge> A promise resolving to { authSession, publicKey }

getSignupChallenge()

Request a passkey signup challenge. Step 1 of the granular signup flow. Returns the auth session and a decoded PublicKeyCredentialCreationOptions. Run the WebAuthn credential creation ceremony with publicKey, then hand the resulting credential and authSession to getTokenWithPasskey().

Parameters

PasskeySignupChallengeOptions
required
Signup challenge options (user identifier, optional realm/organization/metadata)Type: PasskeySignupChallengeOptions

Returns

Promise<PasskeySignupChallenge> A promise resolving to { authSession, publicKey }

getTokenWithPasskey()

Exchange a signed passkey credential for tokens. Step 2 of the granular flow. Serializes the raw PublicKeyCredential produced by the WebAuthn ceremony — either a creation (signup) or an assertion (login) credential — and exchanges it for tokens. The credential type (attestation vs assertion) is detected automatically.

Parameters

PasskeyGetTokenOptions
required
The auth session, raw credential, and optional realm/organization/scope/audienceType: PasskeyGetTokenOptions

Returns

Promise<TokenEndpointResponse> A promise resolving to the token endpoint response

login()

Sign in with an existing passkey. Handles the full flow: requests a login challenge, triggers the browser WebAuthn assertion ceremony, serializes the result, and exchanges it for tokens.

Parameters

PasskeyLoginOptions
Optional passkey login options (optional scope/audience/realm/organization)Type: PasskeyLoginOptions

Returns

Promise<TokenEndpointResponse> A promise that resolves to the token endpoint response containing access/ID tokens

signup()

Register a new user with a passkey. Handles the full flow: requests a signup challenge, triggers the browser WebAuthn credential creation ceremony, serializes the result, and exchanges it for tokens.

Parameters

PasskeySignupOptions
required
Passkey signup options (user identifier, optional scope/audience)Type: PasskeySignupOptions

Returns

Promise<TokenEndpointResponse> A promise that resolves to the token endpoint response containing access/ID tokens