Key terms
How SCA works
SCA uses WebAuthn passkeys to bind end-user approval to a specific operation. Your backend creates a challenge that encodes what the user is approving. Your frontend runs a ceremony in a Circle-hosted iframe. The ceremony returns a signed assertion. You send that assertion as request headers with the API call. There are two distinct flows:Passkey enrollment
Enrollment registers a passkey for an end user. Your backend callsPOST /v1/accounts/passkeys/registrations to open a session and receives a
frame token. Your frontend passes the token to the SDK. The SDK renders a
Circle-hosted iframe where the end user creates a passkey. The SDK returns a
response. Your backend forwards it to POST /v1/accounts/passkeys to finish.
Passkeys may sync across devices through iCloud Keychain, Google Password
Manager, or similar services, based on the end user’s device. A passkey enrolled
on one device may be available on the user’s other devices.
Operation approval
For each operation, your backend callsPOST /v1/accounts/passkeys/challenges
with the operation body as the intent. Circle returns a challenge ID and frame
token. Your frontend passes the token to the SDK’s approve method. The SDK
shows the Circle iframe and prompts the end user to confirm with their passkey.
The SDK returns an assertion string. Your backend sends it as the
X-Sca-Challenge-Id and X-Sca-Assertion headers.
Intent matching
Theintent in the challenge request must match the operation body exactly—same
fields, same values. A missing field, extra field, or value difference returns a
403 with error code 420047. The idempotencyKey must also match in both places.