Skip to main content
POST
Create an SCA challenge

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
clientEntityId
string
required

The end-user identifier initiating the operation.

Example:

"entity_01234567890abcdef"

operation
enum<string>
required

The operation type this challenge authorizes.

Available options:
TRANSFER,
WITHDRAWAL,
ADDRESS_BOOK_ADD,
ADDRESS_BOOK_DELETE,
WIRE_ACCOUNT_CREATE
Example:

"TRANSFER"

intent
object
required

The exact request body you will send to the protected endpoint. Every field and value must match — an extra or missing field causes an intent mismatch error (420047).

Example:
ceremonyKind
string
default:webauthn

The ceremony type to use. Defaults to "webauthn". Any other value, including "spc", is rejected — a typo cannot silently downgrade a ceremony to a weaker mechanism.

Example:

"webauthn"

pathParameters
object

Path parameters for the protected endpoint, if any. Required for ADDRESS_BOOK_DELETE (provide id). Omit for all other operations.

Example:
embedOrigin
string

The origin of your page that embeds the SCA ceremony, for example https://app.example.com. It must exactly match one of the origins approved for your account (scheme, host, and port; no trailing slash or path). Send it on every call. It is required when more than one origin is approved for your account: without it, the request fails with 400. When only one origin is approved, omitting it uses that origin. A blank value, or one that matches none of your approved origins, also fails with 400. The SCA ceremony is bound to this origin: when it is embedded, it can only be completed inside a page on this origin, and it posts its result only to this origin. If this origin is removed from your approved origins before the ceremony completes, the ceremony fails.

Required string length: 1 - 512
Example:

"https://app.example.com"

Response

Successfully created an SCA challenge.

data
object