SCA applies to end users onboarded under Circle’s EU-regulated entity. This is
based on the end user’s legal entity, not your platform’s. Contact your
support team if you are unsure.
The SCA ceremony runs in the browser. There is no iOS, Android, or React
Native SDK for it yet—native applications must host the ceremony in a web view
or the system browser.
Prerequisites
Before you begin, ensure that you’ve:- Registered your application origin with Circle. Reach out to your support team
with the exact origin (scheme + host, for example
https://app.example.com). Registration is required separately for sandbox and production. - Installed the DAA web SDK.
- Obtained a
clientEntityIdfor the end user you’re enrolling. See Onboard customers for how to create one. - Run a device check for the end user and stored the
deviceIdit returned. See Collect device risk signals. Every protected operation below sends thatdeviceIdinriskSignals.
The Digital Asset Accounts API base URL is
https://api-sandbox.circle.com for
sandbox and https://api.circle.com for production. Set your API key in the
Authorization header using the format Bearer YOUR_API_KEY. See
Sandbox environment and
Going to production
for environment details.Steps
Step 1. Enroll a passkey
Enroll a passkey for each end user before they run any protected operation. Run this flow once per end user.Step 1.1. Create a registration session
The frame token expires after 10 minutes. Pass it to your frontend right away.
Do not re-send the request with the same
idempotencyKey after delivering the
token—this rotates the token and invalidates the copy you already sent. Start
a fresh session with a new idempotencyKey if the token expires.Step 1.2. Run the enrollment ceremony
Initialize the SDK on your frontend and callsca.enroll with the frame token
from step 1.1.
The SDK renders the passkey prompt in a Circle-hosted iframe. Pass
attestationResponse to your backend as-is. Re-serializing it causes a
verification error.Step 1.3. complete registration
Send theattestationResponse from the SDK to your backend. Then forward it to
Circle to complete enrollment.
Step 2. Approve a protected operation
For every protected operation, obtain a signed challenge and include it in the API request.Step 2.1. Create a challenge
The
summary is a server-generated record of the operation. Do not use it to
render a pre-confirmation to the end user—the Circle iframe shows its own
description to the user.The frame token expires after 5 minutes. Pass it to your frontend right away.
Re-sending with the same
idempotencyKey rotates the token and invalidates
the copy you already sent. Create a new challenge with a fresh
idempotencyKey if the token expires.Step 2.2. Run the approval ceremony
Pass theframeToken from the challenge response to the SDK’s approve method.
The SDK renders the passkey prompt and returns a signed assertion string.
Step 2.3. Submit the protected operation
Include thechallengeId and assertion as request headers. Use the same field
values you set in the challenge intent.
If a protected endpoint returns HTTP 428 (error code 420058), the
X-Sca-Challenge-Id or X-Sca-Assertion header was omitted from the request.
Run the approval ceremony and retry with both headers present. For other SCA
errors, see the Digital Asset Accounts API
reference.