curl --request POST \
--url https://api-sandbox.circle.com/v1/accounts/passkeys/registrations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"clientEntityId": "entity_01234567890abcdef",
"idempotencyKey": "550e8400-e29b-41d4-a716-446655440000",
"spcCapable": false
}
'import requests
url = "https://api-sandbox.circle.com/v1/accounts/passkeys/registrations"
payload = {
"clientEntityId": "entity_01234567890abcdef",
"idempotencyKey": "550e8400-e29b-41d4-a716-446655440000",
"spcCapable": False
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
clientEntityId: 'entity_01234567890abcdef',
idempotencyKey: '550e8400-e29b-41d4-a716-446655440000',
spcCapable: false
})
};
fetch('https://api-sandbox.circle.com/v1/accounts/passkeys/registrations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-sandbox.circle.com/v1/accounts/passkeys/registrations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientEntityId' => 'entity_01234567890abcdef',
'idempotencyKey' => '550e8400-e29b-41d4-a716-446655440000',
'spcCapable' => false
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-sandbox.circle.com/v1/accounts/passkeys/registrations"
payload := strings.NewReader("{\n \"clientEntityId\": \"entity_01234567890abcdef\",\n \"idempotencyKey\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"spcCapable\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api-sandbox.circle.com/v1/accounts/passkeys/registrations")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"clientEntityId\": \"entity_01234567890abcdef\",\n \"idempotencyKey\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"spcCapable\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-sandbox.circle.com/v1/accounts/passkeys/registrations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientEntityId\": \"entity_01234567890abcdef\",\n \"idempotencyKey\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"spcCapable\": false\n}"
response = http.request(request)
puts response.read_body{
"data": {
"registrationId": "a1b2c3d4-e5f6-7890-ab12-cdef34567890",
"frameToken": "k74ia-AcnTzXtBdxnbVqn1IBpVUXBbhGiGxQkGD386A",
"expiresAt": "2026-09-24T12:10:00Z"
}
}{
"code": 2,
"message": "API parameter invalid."
}{
"code": 4,
"message": "Unauthorized."
}{
"code": 2,
"message": "API parameter invalid.",
"externalMessage": "The provided amount exceeds the maximum allowed.",
"errors": [
{
"error": "invalid_value",
"message": "The operation and assetType combination is invalid.",
"location": "assetType"
}
]
}{
"code": -1,
"message": "Something went wrong. errId: 1f0b0c455e40f753f07b4f0ae6abd4b4"
}Open a passkey registration session
Creates a short-lived registration session (10-minute TTL) that coordinates WebAuthn passkey enrollment for an end user. Pass the returned frameToken to the DAA web SDK’s sca.enroll method to run the enrollment ceremony.
curl --request POST \
--url https://api-sandbox.circle.com/v1/accounts/passkeys/registrations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"clientEntityId": "entity_01234567890abcdef",
"idempotencyKey": "550e8400-e29b-41d4-a716-446655440000",
"spcCapable": false
}
'import requests
url = "https://api-sandbox.circle.com/v1/accounts/passkeys/registrations"
payload = {
"clientEntityId": "entity_01234567890abcdef",
"idempotencyKey": "550e8400-e29b-41d4-a716-446655440000",
"spcCapable": False
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
clientEntityId: 'entity_01234567890abcdef',
idempotencyKey: '550e8400-e29b-41d4-a716-446655440000',
spcCapable: false
})
};
fetch('https://api-sandbox.circle.com/v1/accounts/passkeys/registrations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-sandbox.circle.com/v1/accounts/passkeys/registrations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientEntityId' => 'entity_01234567890abcdef',
'idempotencyKey' => '550e8400-e29b-41d4-a716-446655440000',
'spcCapable' => false
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-sandbox.circle.com/v1/accounts/passkeys/registrations"
payload := strings.NewReader("{\n \"clientEntityId\": \"entity_01234567890abcdef\",\n \"idempotencyKey\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"spcCapable\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api-sandbox.circle.com/v1/accounts/passkeys/registrations")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"clientEntityId\": \"entity_01234567890abcdef\",\n \"idempotencyKey\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"spcCapable\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-sandbox.circle.com/v1/accounts/passkeys/registrations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientEntityId\": \"entity_01234567890abcdef\",\n \"idempotencyKey\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"spcCapable\": false\n}"
response = http.request(request)
puts response.read_body{
"data": {
"registrationId": "a1b2c3d4-e5f6-7890-ab12-cdef34567890",
"frameToken": "k74ia-AcnTzXtBdxnbVqn1IBpVUXBbhGiGxQkGD386A",
"expiresAt": "2026-09-24T12:10:00Z"
}
}{
"code": 2,
"message": "API parameter invalid."
}{
"code": 4,
"message": "Unauthorized."
}{
"code": 2,
"message": "API parameter invalid.",
"externalMessage": "The provided amount exceeds the maximum allowed.",
"errors": [
{
"error": "invalid_value",
"message": "The operation and assetType combination is invalid.",
"location": "assetType"
}
]
}{
"code": -1,
"message": "Something went wrong. errId: 1f0b0c455e40f753f07b4f0ae6abd4b4"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
The end-user identifier to enroll.
"entity_01234567890abcdef"
A unique key for this registration session. Replaying the same key for the same clientEntityId and spcCapable returns the original session unchanged. Using the same key for a different clientEntityId or spcCapable value returns 409.
"550e8400-e29b-41d4-a716-446655440000"
Whether this credential should be marked as eligible for Secure Payment Confirmation (SPC). Defaults to false. This flag is recorded permanently at enrollment and cannot be changed later.
Response
Successfully opened a passkey registration session.
Show child attributes
Show child attributes
Was this page helpful?