Skip to main content
POST
Create an SCA challenge

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
clientEntityId
string
required

The end-user identifier initiating the operation.

Example:

"entity_01234567890abcdef"

operation
enum<string>
required

The operation type this challenge authorizes.

Available options:
TRANSFER,
WITHDRAWAL,
ADDRESS_BOOK_ADD,
ADDRESS_BOOK_DELETE,
WIRE_ACCOUNT_CREATE
Example:

"TRANSFER"

intent
object
required

The exact request body you will send to the protected endpoint. Every field and value must match — an extra or missing field causes an intent mismatch error (420047).

Example:
ceremonyKind
string
default:webauthn

The ceremony type to use. Defaults to "webauthn". Any other value, including "spc", is rejected — a typo cannot silently downgrade a ceremony to a weaker mechanism.

Example:

"webauthn"

pathParameters
object

Path parameters for the protected endpoint, if any. Required for ADDRESS_BOOK_DELETE (provide id). Omit for all other operations.

Example:

Response

Successfully created an SCA challenge.

data
object