> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an SCA challenge

> Creates a short-lived, single-use challenge (5-minute TTL) that captures the intent of a protected operation. Pass the returned `frameToken` to the DAA web SDK's `sca.approve` method to produce a signed assertion. The `intent` must exactly match the request body you will send to the protected endpoint — same fields, same values.




## OpenAPI

````yaml openapi/accounts.yaml post /v1/accounts/passkeys/challenges
openapi: 3.1.0
info:
  version: 1.0.0
  title: Accounts (Stablecoin) API
  description: >
    Circle's Accounts API provides endpoints for managing stablecoin accounts --
    including transfers,

    withdrawals, deposits, wire and ACH bank accounts, and blockchain addresses.


    An **Account** is a general representation of a ledger or custody object
    that holds balances. It can be a business account,

    a stablecoin account ledger for an end user, an extra sub-ledger, or any
    future custody solution.
  license:
    name: Circle License
    url: https://circle.com/terms
servers:
  - url: https://api-sandbox.circle.com
  - url: https://api.circle.com
security: []
tags:
  - name: Accounts
    description: Manage accounts.
  - name: Account Groups
    description: Manage custody account groups and their memberships.
  - name: Limits
    description: View effective account limits and current usage.
  - name: Transfers
    description: Manage account transfers.
  - name: Transactions
    description: |
      Get a unified, customer-friendly view of account transaction activity.
  - name: Wires
    description: Manage account bank accounts for wire transfers.
  - name: Deposits
    description: Get information on account bank deposits.
  - name: Withdrawals
    description: Manage account bank withdrawals (fiat offramp).
  - name: ACH
    description: Manage account bank accounts for ACH transfers.
  - name: Deposit Addresses
    description: Manage account deposit addresses.
  - name: Recipient Addresses
    description: Manage account recipient addresses used for transfers.
  - name: Passkeys
    description: >
      Manage WebAuthn passkeys and Strong Customer Authentication (SCA)
      challenges for end users.
  - name: Webhook Subscriptions
    description: Manage subscriptions to Digital Asset Accounts webhook notifications.
paths:
  /v1/accounts/passkeys/challenges:
    post:
      tags:
        - Passkeys
      summary: Create an SCA challenge
      description: >
        Creates a short-lived, single-use challenge (5-minute TTL) that captures
        the intent of a protected operation. Pass the returned `frameToken` to
        the DAA web SDK's `sca.approve` method to produce a signed assertion.
        The `intent` must exactly match the request body you will send to the
        protected endpoint — same fields, same values.
      operationId: createScaChallenge
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ScaChallengeRequest'
      responses:
        '201':
          description: Successfully created an SCA challenge.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateScaChallengeResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/NotAuthorized'
        '404':
          description: >
            The `addressId` or destination account referenced in the challenge
            `intent` does not exist or does not belong to this entity.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - bearerAuth: []
components:
  schemas:
    ScaChallengeRequest:
      type: object
      required:
        - clientEntityId
        - operation
        - intent
      properties:
        clientEntityId:
          type: string
          description: The end-user identifier initiating the operation.
          example: entity_01234567890abcdef
        operation:
          $ref: '#/components/schemas/ScaOperation'
        intent:
          type: object
          description: >
            The exact request body you will send to the protected endpoint.
            Every field and value must match — an extra or missing field causes
            an intent mismatch error (420047).
          additionalProperties: true
          example:
            idempotencyKey: 550e8400-e29b-41d4-a716-446655440000
            source:
              type: account
              id: '1017381855'
            destination:
              type: verified_blockchain
              addressId: c7d8e9f0-a1b2-3456-7890-abcdef123456
            amount:
              amount: '50.00'
              currency: USD
            riskSignals:
              ipAddress: 203.0.113.42
              sessionId: sess_abcdefghij
              deviceId: dev_klmnopqrst
        ceremonyKind:
          type: string
          description: >
            The ceremony type to use. Defaults to `"webauthn"`. Any other value,
            including `"spc"`, is rejected — a typo cannot silently downgrade a
            ceremony to a weaker mechanism.
          default: webauthn
          example: webauthn
        pathParameters:
          type: object
          description: >
            Path parameters for the protected endpoint, if any. Required for
            `ADDRESS_BOOK_DELETE` (provide `id`). Omit for all other operations.
          additionalProperties: true
          example:
            id: a1b2c3d4-e5f6-7890-ab12-cdef34567890
    CreateScaChallengeResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            challengeId:
              type: string
              format: uuid
              description: >
                The challenge identifier. Pass this as the `X-Sca-Challenge-Id`
                header on the protected endpoint request.
              example: b2c3d4e5-f6a7-8901-bc23-def456789012
            frameToken:
              type: string
              description: >
                Opaque token that authorizes the approval ceremony iframe. Pass
                it to the DAA web SDK's `sca.approve` method immediately.
                Expires after 5 minutes. Re-sending this request with the same
                `idempotencyKey` rotates the token and invalidates any token
                already delivered to the frontend.
              example: k74ia-AcnTzXtBdxnbVqn1IBpVUXBbhGiGxQkGD386A
            expiresAt:
              type: string
              format: date-time
              description: When the challenge expires (5-minute TTL).
              example: '2026-09-24T12:05:00Z'
            summary:
              $ref: '#/components/schemas/ChallengeSummary'
          required:
            - challengeId
            - frameToken
            - expiresAt
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: integer
          description: >
            Circle internal status code from the platform `CoreStatusCode` enum
            (and its domain-specific extensions). **This is not the HTTP status
            code** — `-1` is the catch-all unknown error, `1`/`2` indicate API
            parameter problems, `3` is forbidden, `4` is unauthorized, and
            larger values identify domain-specific failures. Consumers should
            rely on the HTTP status line for transport-level error class and on
            this field for the specific Circle error case.
          example: 2
        message:
          type: string
          description: >-
            Internal error message; suitable for logging but not for end-user
            display.
          example: API parameter invalid.
        externalMessage:
          type: string
          description: >
            End-user-displayable error message. Present when the server has
            generated a customer-facing variant for this error; omitted
            otherwise.
          example: The provided amount exceeds the maximum allowed.
        errors:
          type: array
          description: Additional request-field validation errors, when available.
          items:
            $ref: '#/components/schemas/ErrorDetail'
    ScaOperation:
      type: string
      description: The operation type this challenge authorizes.
      enum:
        - TRANSFER
        - WITHDRAWAL
        - ADDRESS_BOOK_ADD
        - ADDRESS_BOOK_DELETE
        - WIRE_ACCOUNT_CREATE
      example: TRANSFER
    XRequestId:
      type: string
      format: uuid
      example: 2adba88e-9d63-44bc-b975-9b6ae3440dde
    ChallengeSummary:
      type: object
      description: >
        A server-generated structured summary of the challenge intent. This is
        for your records only — do not use it to render a pre-confirmation UI.
        The Circle ceremony iframe independently fetches and displays the
        operation description that the end user approves.
      properties:
        type:
          type: string
          description: The type of operation.
          example: transfer
        amount:
          type: object
          properties:
            amount:
              type: string
              example: '50.00'
            currency:
              type: string
              example: USD
        destination:
          type: string
          description: Display identifier of the destination.
          example: '1001587127'
        sourceAccountLabel:
          type: string
          description: Display label of the source account.
          example: My DAA account
    ErrorDetail:
      type: object
      required:
        - error
        - message
      properties:
        error:
          type: string
          description: Machine-readable error identifier.
          example: invalid_value
        location:
          type: string
          description: Query parameter or request field that caused the error.
          example: assetType
        message:
          type: string
          description: Human-readable description of the specific error.
          example: The operation and assetType combination is invalid.
  headers:
    XRequestId:
      description: >
        Circle-generated universally unique identifier (UUID v4). Useful for
        identifying a specific request when communicating with Circle Support.
      schema:
        $ref: '#/components/schemas/XRequestId'
  responses:
    BadRequest:
      description: The request cannot be processed due to a client error.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 2
            message: API parameter invalid.
    NotAuthorized:
      description: >-
        The request has not been applied because it lacks valid authentication
        credentials.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 4
            message: Unauthorized.
    InternalServerError:
      description: >-
        The server encountered an unexpected condition that prevented it from
        fulfilling the request.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: -1
            message: 'Something went wrong. errId: 1f0b0c455e40f753f07b4f0ae6abd4b4'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````