signup— Register a new user with a passkey (full flow: challenge → WebAuthn → token exchange)login— Sign in with a passkey (full flow: challenge → WebAuthn → token exchange)
Methods
getLoginChallenge()
PublicKeyCredentialRequestOptions. Run the WebAuthn assertion
ceremony with publicKey, then hand the resulting credential and authSession to
getTokenWithPasskey().
Parameters
PasskeyLoginChallengeOptions
Optional login challenge options (realm/organization)Type: PasskeyLoginChallengeOptions
Returns
Promise<PasskeyLoginChallenge>
A promise resolving to { authSession, publicKey }
getSignupChallenge()
PublicKeyCredentialCreationOptions. Run the WebAuthn credential
creation ceremony with publicKey, then hand the resulting credential and authSession to
getTokenWithPasskey().
Parameters
PasskeySignupChallengeOptions
required
Signup challenge options (user identifier, optional realm/organization/metadata)Type: PasskeySignupChallengeOptions
Returns
Promise<PasskeySignupChallenge>
A promise resolving to { authSession, publicKey }
getTokenWithPasskey()
PublicKeyCredential
produced by the WebAuthn ceremony — either a creation (signup) or an
assertion (login) credential — and exchanges it for tokens. The credential
type (attestation vs assertion) is detected automatically.
Parameters
PasskeyGetTokenOptions
required
The auth session, raw credential, and optional realm/organization/scope/audienceType: PasskeyGetTokenOptions
Returns
Promise<TokenEndpointResponse>
A promise resolving to the token endpoint response
login()
Parameters
PasskeyLoginOptions
Optional passkey login options (optional scope/audience/realm/organization)Type: PasskeyLoginOptions
Returns
Promise<TokenEndpointResponse>
A promise that resolves to the token endpoint response containing access/ID tokens
signup()
Parameters
PasskeySignupOptions
required
Passkey signup options (user identifier, optional scope/audience)Type: PasskeySignupOptions
Returns
Promise<TokenEndpointResponse>
A promise that resolves to the token endpoint response containing access/ID tokens