> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Strong Customer Authentication

> How WebAuthn passkeys and the challenge–assertion flow protect sensitive operations for Digital Asset Account end users.

Strong Customer Authentication (SCA) requires end users to approve sensitive
operations before Circle processes them. Each approval is bound to a specific
operation and cannot be reused. SCA applies to end users onboarded under
Circle's EU-regulated entity—based on the end user's legal entity, not your
platform's.

## Key terms

| Term                                     | Description                                                                                                                                                             |
| ---------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Passkey                                  | A WebAuthn credential on the end user's device (biometric sensor, Face ID, Windows Hello, or security key). Passkeys may sync across devices depending on the platform. |
| Origin                                   | Your app's domain (scheme + host). Passkeys are tied to a registered origin.                                                                                            |
| Registration session                     | A short-lived object that coordinates passkey enrollment. Expires in 10 minutes.                                                                                        |
| Challenge                                | A short-lived, single-use object that captures the intent of an operation. Expires in 5 minutes.                                                                        |
| Intent                                   | The operation body signed into a challenge. Must match the API request exactly.                                                                                         |
| Frame token                              | An opaque token from Circle that authorizes the ceremony iframe.                                                                                                        |
| `X-Sca-Challenge-Id` / `X-Sca-Assertion` | Request headers that carry the signed challenge for SCA-gated endpoints.                                                                                                |

## How SCA works

SCA uses WebAuthn passkeys to bind end-user approval to a specific operation.
Your backend creates a challenge that encodes what the user is approving. Your
frontend runs a ceremony in a Circle-hosted iframe. The ceremony returns a
signed assertion. You send that assertion as request headers with the API call.

There are two distinct flows:

| Flow               | When to run                                            |
| ------------------ | ------------------------------------------------------ |
| Passkey enrollment | Once per end user, before any protected operation      |
| Operation approval | Every time an end user initiates a protected operation |

### Passkey enrollment

Enrollment registers a passkey for an end user. Your backend calls
`POST /v1/accounts/passkeys/registrations` to open a session and receives a
frame token. Your frontend passes the token to the SDK. The SDK renders a
Circle-hosted iframe where the end user creates a passkey. The SDK returns a
response. Your backend forwards it to `POST /v1/accounts/passkeys` to finish.

Passkeys may sync across devices through iCloud Keychain, Google Password
Manager, or similar services, based on the end user's device. A passkey enrolled
on one device may be available on the user's other devices.

### Operation approval

For each operation, your backend calls `POST /v1/accounts/passkeys/challenges`
with the operation body as the `intent`. Circle returns a challenge ID and frame
token. Your frontend passes the token to the SDK's `approve` method. The SDK
shows the Circle iframe and prompts the end user to confirm with their passkey.
The SDK returns an assertion string. Your backend sends it as the
`X-Sca-Challenge-Id` and `X-Sca-Assertion` headers.

### Intent matching

The `intent` in the challenge request must match the operation body exactly—same
fields, same values. A missing field, extra field, or value difference returns a
403 with error code 420047. The `idempotencyKey` must also match in both places.

## Protected endpoints

The following endpoints require SCA headers for EU-regulated end users:

| Method | Endpoint                                                                                             | Operation                             |
| ------ | ---------------------------------------------------------------------------------------------------- | ------------------------------------- |
| POST   | [`/v1/accounts/transfers`](/api-reference/digital-asset-accounts/all/create-account-transfer)        | Crypto or account-to-account transfer |
| POST   | [`/v1/accounts/withdrawals`](/api-reference/digital-asset-accounts/all/create-account-withdrawal)    | Wire withdrawal                       |
| POST   | [`/v1/addresses/recipient`](/api-reference/digital-asset-accounts/all/create-recipient-address)      | Add recipient blockchain address      |
| DELETE | [`/v1/addresses/recipient/{id}`](/api-reference/digital-asset-accounts/all/delete-recipient-address) | Remove recipient blockchain address   |
| POST   | [`/v1/banks/wires`](/api-reference/digital-asset-accounts/all/create-wire-account)                   | Link a wire bank account              |
