Skip to main content
Strong Customer Authentication (SCA) requires end users to approve sensitive operations before Circle processes them. Each approval is bound to a specific operation and cannot be reused. SCA applies to end users onboarded under Circle’s EU-regulated entity—based on the end user’s legal entity, not your platform’s.

Key terms

How SCA works

SCA uses WebAuthn passkeys to bind end-user approval to a specific operation. Your backend creates a challenge that encodes what the user is approving. Your frontend runs a ceremony in a Circle-hosted iframe. The ceremony returns a signed assertion. You send that assertion as request headers with the API call. There are two distinct flows:

Passkey enrollment

Enrollment registers a passkey for an end user. Your backend calls POST /v1/accounts/passkeys/registrations to open a session and receives a frame token. Your frontend passes the token to the SDK. The SDK renders a Circle-hosted iframe where the end user creates a passkey. The SDK returns a response. Your backend forwards it to POST /v1/accounts/passkeys to finish. Passkeys may sync across devices through iCloud Keychain, Google Password Manager, or similar services, based on the end user’s device. A passkey enrolled on one device may be available on the user’s other devices.

Operation approval

For each operation, your backend calls POST /v1/accounts/passkeys/challenges with the operation body as the intent. Circle returns a challenge ID and frame token. Your frontend passes the token to the SDK’s approve method. The SDK shows the Circle iframe and prompts the end user to confirm with their passkey. The SDK returns an assertion string. Your backend sends it as the X-Sca-Challenge-Id and X-Sca-Assertion headers.

Intent matching

The intent in the challenge request must match the operation body exactly—same fields, same values. A missing field, extra field, or value difference returns a 403 with error code 420047. The idempotencyKey must also match in both places.

Protected endpoints

The following endpoints require SCA headers for EU-regulated end users: