> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# Create an SCA challenge

> Creates a short-lived, single-use challenge (5-minute TTL) that captures the intent of a protected operation. Pass the returned `frameToken` to the DAA web SDK's `sca.approve` method to produce a signed assertion. The `intent` must exactly match the request body you will send to the protected endpoint — same fields, same values.




## OpenAPI

````yaml openapi/accounts.yaml post /v1/accounts/passkeys/challenges
openapi: 3.1.0
info:
  version: 1.0.0
  title: Accounts (Stablecoin) API
  description: >
    Circle's Accounts API provides endpoints for managing stablecoin accounts --
    including transfers,

    withdrawals, deposits, wire and ACH bank accounts, and blockchain addresses.


    An **Account** is a general representation of a ledger or custody object
    that holds balances. It can be a business account,

    a stablecoin account ledger for an end user, an extra sub-ledger, or any
    future custody solution.
  license:
    name: Circle License
    url: https://circle.com/terms
servers:
  - url: https://api-sandbox.circle.com
  - url: https://api.circle.com
security: []
tags:
  - name: Accounts
    description: Manage accounts.
  - name: Account Groups
    description: Manage custody account groups and their memberships.
  - name: Limits
    description: View effective account limits and current usage.
  - name: Transfers
    description: Manage account transfers.
  - name: Transactions
    description: |
      Get a unified, customer-friendly view of account transaction activity.
  - name: Wires
    description: Manage account bank accounts for wire transfers.
  - name: Deposits
    description: Get information on account bank deposits.
  - name: Withdrawals
    description: Manage account bank withdrawals (fiat offramp).
  - name: ACH
    description: Manage account bank accounts for ACH transfers.
  - name: Deposit Addresses
    description: Manage account deposit addresses.
  - name: Recipient Addresses
    description: Manage account recipient addresses used for transfers.
  - name: Passkeys
    description: >
      Manage WebAuthn passkeys and Strong Customer Authentication (SCA)
      challenges for end users.
  - name: Crypto Payments
    description: >
      Get crypto payments and crypto refunds received through payment intents.
      Available for Digital Asset Accounts only on custody accounts (`purpose:
      custody`), and only for third-party payments. Not supported when the
      distributor or the end user is under the Circle FR (`CIRCLE_FR`) or Circle
      SG (`CIRCLE_SG`) legal entity.
  - name: Crypto Payment Intents
    description: >
      Create, expire, refund, and track payment intents for receiving crypto
      payments. Available for Digital Asset Accounts only on custody accounts
      (`purpose: custody`), and only for third-party payments. Not supported
      when the distributor or the end user is under the Circle FR (`CIRCLE_FR`)
      or Circle SG (`CIRCLE_SG`) legal entity.
  - name: Crypto Payouts
    description: >
      Create and track crypto payouts to recipient addresses. Available for
      Digital Asset Accounts only on custody accounts (`purpose: custody`), and
      only for third-party payouts. Not supported when the distributor or the
      end user is under the Circle FR (`CIRCLE_FR`) or Circle SG (`CIRCLE_SG`)
      legal entity.
  - name: Crypto Address Book
    description: >
      Manage address book recipients used as crypto payout destinations.
      Available for Digital Asset Accounts only on custody accounts (`purpose:
      custody`), and only for third-party payouts. Not supported when the
      distributor or the end user is under the Circle FR (`CIRCLE_FR`) or Circle
      SG (`CIRCLE_SG`) legal entity.
  - name: Webhook Subscriptions
    description: Manage subscriptions to Digital Asset Accounts webhook notifications.
paths:
  /v1/accounts/passkeys/challenges:
    post:
      tags:
        - Passkeys
      summary: Create an SCA challenge
      description: >
        Creates a short-lived, single-use challenge (5-minute TTL) that captures
        the intent of a protected operation. Pass the returned `frameToken` to
        the DAA web SDK's `sca.approve` method to produce a signed assertion.
        The `intent` must exactly match the request body you will send to the
        protected endpoint — same fields, same values.
      operationId: createScaChallenge
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ScaChallengeRequest'
      responses:
        '201':
          description: Successfully created an SCA challenge.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateScaChallengeResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/NotAuthorized'
        '404':
          description: >
            The `addressId` or destination account referenced in the challenge
            `intent` does not exist or does not belong to this entity.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          $ref: '#/components/responses/RequestTooLarge'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - bearerAuth: []
components:
  schemas:
    ScaChallengeRequest:
      type: object
      required:
        - clientEntityId
        - operation
        - intent
      properties:
        clientEntityId:
          type: string
          description: The end-user identifier initiating the operation.
          example: entity_01234567890abcdef
        operation:
          $ref: '#/components/schemas/ScaOperation'
        intent:
          type: object
          description: >
            The exact request body you will send to the protected endpoint.
            Every field and value must match — an extra or missing field causes
            an intent mismatch error (420047).
          additionalProperties: true
          example:
            idempotencyKey: 550e8400-e29b-41d4-a716-446655440000
            source:
              type: account
              id: '1017381855'
            destination:
              type: verified_blockchain
              addressId: c7d8e9f0-a1b2-3456-7890-abcdef123456
            amount:
              amount: '50.00'
              currency: USD
            riskSignals:
              ipAddress: 203.0.113.42
              sessionId: sess_abcdefghij
              deviceId: dev_klmnopqrst
        ceremonyKind:
          type: string
          description: >
            The ceremony type to use. Defaults to `"webauthn"`. Any other value,
            including `"spc"`, is rejected — a typo cannot silently downgrade a
            ceremony to a weaker mechanism.
          default: webauthn
          example: webauthn
        pathParameters:
          type: object
          description: >
            Path parameters for the protected endpoint, if any. Required for
            `ADDRESS_BOOK_DELETE` (provide `id`). Omit for all other operations.
          additionalProperties: true
          example:
            id: a1b2c3d4-e5f6-7890-ab12-cdef34567890
        embedOrigin:
          type: string
          minLength: 1
          maxLength: 512
          description: >
            The origin of your page that embeds the SCA ceremony, for example
            `https://app.example.com`. It must exactly match one of the origins
            approved for your account (scheme, host, and port; no trailing slash
            or path). Send it on every call. It is required when more than one
            origin is approved for your account: without it, the request fails
            with `400`. When only one origin is approved, omitting it uses that
            origin. A blank value, or one that matches none of your approved
            origins, also fails with `400`. The SCA ceremony is bound to this
            origin: when it is embedded, it can only be completed inside a page
            on this origin, and it posts its result only to this origin. If this
            origin is removed from your approved origins before the ceremony
            completes, the ceremony fails.
          example: https://app.example.com
    CreateScaChallengeResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            challengeId:
              type: string
              format: uuid
              description: >
                The challenge identifier. Pass this as the `X-Sca-Challenge-Id`
                header on the protected endpoint request.
              example: b2c3d4e5-f6a7-8901-bc23-def456789012
            frameToken:
              type: string
              description: >
                Opaque token that authorizes the approval ceremony iframe. Pass
                it to the DAA web SDK's `sca.approve` method immediately.
                Expires after 5 minutes. Re-sending this request with the same
                `idempotencyKey` rotates the token and invalidates any token
                already delivered to the frontend.
              example: k74ia-AcnTzXtBdxnbVqn1IBpVUXBbhGiGxQkGD386A
            expiresAt:
              type: string
              format: date-time
              description: When the challenge expires (5-minute TTL).
              example: '2026-09-24T12:05:00Z'
            summary:
              $ref: '#/components/schemas/ChallengeSummary'
          required:
            - challengeId
            - frameToken
            - expiresAt
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: integer
          description: >
            Circle internal status code from the platform `CoreStatusCode` enum
            (and its domain-specific extensions). **This is not the HTTP status
            code** — `-1` is the catch-all unknown error, `1`/`2` indicate API
            parameter problems, `3` is forbidden, `4` is unauthorized, and
            larger values identify domain-specific failures. Consumers should
            rely on the HTTP status line for transport-level error class and on
            this field for the specific Circle error case.
          example: 2
        message:
          type: string
          description: >-
            Internal error message; suitable for logging but not for end-user
            display.
          example: API parameter invalid.
        externalMessage:
          type: string
          description: >
            End-user-displayable error message. Present when the server has
            generated a customer-facing variant for this error; omitted
            otherwise.
          example: The provided amount exceeds the maximum allowed.
        errors:
          type: array
          description: Additional request-field validation errors, when available.
          items:
            $ref: '#/components/schemas/ErrorDetail'
    ScaOperation:
      type: string
      description: The operation type this challenge authorizes.
      enum:
        - TRANSFER
        - WITHDRAWAL
        - ADDRESS_BOOK_ADD
        - ADDRESS_BOOK_DELETE
        - WIRE_ACCOUNT_CREATE
      example: TRANSFER
    XRequestId:
      type: string
      format: uuid
      example: 2adba88e-9d63-44bc-b975-9b6ae3440dde
    ChallengeSummary:
      type: object
      description: >
        A server-generated structured summary of the challenge intent. This is
        for your records only — do not use it to render a pre-confirmation UI.
        The Circle ceremony iframe independently fetches and displays the
        operation description that the end user approves.
      properties:
        type:
          type: string
          description: The type of operation.
          example: transfer
        amount:
          type: object
          properties:
            amount:
              type: string
              example: '50.00'
            currency:
              type: string
              example: USD
        destination:
          type: string
          description: Display identifier of the destination.
          example: '1001587127'
        sourceAccountLabel:
          type: string
          description: Display label of the source account.
          example: My DAA account
    ErrorDetail:
      type: object
      required:
        - error
        - message
      properties:
        error:
          type: string
          description: Machine-readable error identifier.
          example: invalid_value
        location:
          type: string
          description: Query parameter or request field that caused the error.
          example: assetType
        message:
          type: string
          description: Human-readable description of the specific error.
          example: The operation and assetType combination is invalid.
  headers:
    XRequestId:
      description: >
        Circle-generated universally unique identifier (UUID v4). Useful for
        identifying a specific request when communicating with Circle Support.
      schema:
        $ref: '#/components/schemas/XRequestId'
  responses:
    BadRequest:
      description: The request cannot be processed due to a client error.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 2
            message: API parameter invalid.
    NotAuthorized:
      description: >-
        The request has not been applied because it lacks valid authentication
        credentials.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 4
            message: Unauthorized.
    RequestTooLarge:
      description: |
        The request body or the `X-Sca-Assertion` or `X-Sca-Challenge-Id` header
        is too large to process (error code 420067). A request built from valid
        field values is always within the limit, so check the body and headers
        for an oversized or unexpected value. Retrying the same request returns
        the same error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: >-
        The server encountered an unexpected condition that prevented it from
        fulfilling the request.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: -1
            message: 'Something went wrong. errId: 1f0b0c455e40f753f07b4f0ae6abd4b4'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````