openapi: 3.0.3
info:
version: 1.66.0
title: FusionAuth Api Key Webauthn API
description: This is a FusionAuth server. Find out more at [https://fusionauth.io](https://fusionauth.io). You need to [set up an API key](https://fusionauth.io/docs/v1/tech/apis/authentication#managing-api-keys) in the FusionAuth instance you are using to test out the API calls.
license:
name: Apache2
servers:
- url: http://localhost:9011
- url: https://sandbox.fusionauth.io
security:
- ApiKeyAuth: []
tags:
- name: Webauthn
paths:
/api/webauthn:
delete:
description: Deletes all of the WebAuthn credentials for the given User Id.
operationId: deleteWebAuthnCredentialsForUserWithId
parameters:
- name: userId
in: query
schema:
type: string
description: The unique Id of the User to delete WebAuthn passkeys for.
responses:
'200':
description: Success
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
get:
description: Retrieves all WebAuthn credentials for the given user.
operationId: retrieveWebAuthnCredentialsForUserWithId
parameters:
- name: userId
in: query
schema:
type: string
description: The user's ID.
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnCredentialResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/assert:
post:
description: Complete a WebAuthn authentication ceremony by validating the signature against the previously generated challenge without logging the user in
operationId: completeWebAuthnAssertionWithId
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnLoginRequest'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnAssertResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/import:
post:
description: Import a WebAuthn credential
operationId: importWebAuthnCredentialWithId
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnCredentialImportRequest'
responses:
'200':
description: Success
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/login:
post:
description: Complete a WebAuthn authentication ceremony by validating the signature against the previously generated challenge and then login the user in
operationId: completeWebAuthnLoginWithId
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnLoginRequest'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/LoginResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/register/complete:
post:
description: Complete a WebAuthn registration ceremony by validating the client request and saving the new credential
operationId: completeWebAuthnRegistrationWithId
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnRegisterCompleteRequest'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnRegisterCompleteResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/register/start:
post:
description: Start a WebAuthn registration ceremony by generating a new challenge for the user
operationId: startWebAuthnRegistrationWithId
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnRegisterStartRequest'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnRegisterStartResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/start:
post:
description: Start a WebAuthn authentication ceremony by generating a new challenge for the user
operationId: startWebAuthnLoginWithId
parameters: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnStartRequest'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnStartResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
/api/webauthn/{id}:
delete:
description: Deletes the WebAuthn credential for the given Id.
operationId: deleteWebAuthnCredentialWithId
parameters:
- name: id
in: path
schema:
type: string
required: true
description: The Id of the WebAuthn credential to delete.
responses:
'200':
description: Success
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
get:
description: Retrieves the WebAuthn credential for the given Id.
operationId: retrieveWebAuthnCredentialWithId
parameters:
- name: id
in: path
schema:
type: string
required: true
description: The Id of the WebAuthn credential.
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/WebAuthnCredentialResponse'
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
tags:
- Webauthn
components:
schemas:
IdentityVerifiedReason:
description: Models the reason that {@link UserIdentity#verified} was set to true or false.
type: string
enum:
- Skipped
- Trusted
- Unverifiable
- Implicit
- Pending
- Completed
- Disabled
- Administrative
- Import
Errors:
description: Standard error domain object that can also be used as the response from an API call.
type: object
properties:
fieldErrors:
type: array
items:
$ref: '#/components/schemas/Error'
generalErrors:
type: array
items:
$ref: '#/components/schemas/Error'
UserVerificationRequirement:
description: Used to express whether the Relying Party requires user verification for the current operation.
type: string
enum:
- required
- preferred
- discouraged
ZonedDateTime:
description: 'The number of milliseconds since the unix epoch: January 1, 1970 00:00:00 UTC. This value is always in UTC.'
example: '1659380719000'
type: integer
format: int64
ResidentKeyRequirement:
description: Describes the Relying Party's requirements for client-side discoverable credentials (formerly known as "resident keys")
type: string
enum:
- discouraged
- preferred
- required
WebAuthnRegisterStartRequest:
description: API request to start a WebAuthn registration ceremony
type: object
properties:
displayName:
type: string
name:
type: string
userAgent:
type: string
userId:
type: string
format: uuid
workflow:
$ref: '#/components/schemas/WebAuthnWorkflow'
WebAuthnPublicKeyAuthenticationRequest:
description: Request to authenticate with WebAuthn
type: object
properties:
clientExtensionResults:
$ref: '#/components/schemas/WebAuthnExtensionsClientOutputs'
id:
type: string
rpId:
type: string
response:
$ref: '#/components/schemas/WebAuthnAuthenticatorAuthenticationResponse'
type:
type: string
WebAuthnCredentialResponse:
description: WebAuthn Credential API response
type: object
properties:
credential:
$ref: '#/components/schemas/WebAuthnCredential'
credentials:
type: array
items:
$ref: '#/components/schemas/WebAuthnCredential'
WebAuthnAssertResponse:
description: API response for completing WebAuthn assertion
type: object
properties:
credential:
$ref: '#/components/schemas/WebAuthnCredential'
Locale:
description: A Locale object represents a specific geographical, political, or cultural region.
example: en_US
type: string
WebAuthnAuthenticatorRegistrationResponse:
description: The authenticator's response for the registration ceremony in its encoded format
type: object
properties:
attestationObject:
type: string
clientDataJSON:
type: string
ContentStatus:
description: Status for content like usernames, profile attributes, etc.
type: string
enum:
- ACTIVE
- PENDING
- REJECTED
TOTPAlgorithm:
type: string
enum:
- HmacSHA1
- HmacSHA256
- HmacSHA512
MetaData:
type: object
properties:
data:
type: object
additionalProperties:
type: object
device:
$ref: '#/components/schemas/DeviceInfo'
scopes:
type: array
uniqueItems: true
items: {}
UserRegistration:
description: User registration information for a single application.
type: object
properties:
data:
type: object
additionalProperties:
type: object
preferredLanguages:
type: array
items:
$ref: '#/components/schemas/Locale'
tokens:
type: object
additionalProperties:
type: string
applicationId:
type: string
format: uuid
authenticationToken:
type: string
cleanSpeakId:
type: string
format: uuid
id:
type: string
format: uuid
insertInstant:
$ref: '#/components/schemas/ZonedDateTime'
lastLoginInstant:
$ref: '#/components/schemas/ZonedDateTime'
lastUpdateInstant:
$ref: '#/components/schemas/ZonedDateTime'
roles:
type: array
uniqueItems: true
items: {}
timezone:
$ref: '#/components/schemas/ZoneId'
username:
type: string
usernameStatus:
$ref: '#/components/schemas/ContentStatus'
verified:
type: boolean
verifiedInstant:
$ref: '#/components/schemas/ZonedDateTime'
AuthenticatorSelectionCriteria:
description: Used by the Relying Party to specify their requirements for authenticator attributes. Fields use the deprecated "resident key" terminology to refer to client-side discoverable credentials to maintain backwards compatibility with WebAuthn Level 1.
type: object
properties:
authenticatorAttachment:
$ref: '#/components/schemas/AuthenticatorAttachment'
requireResidentKey:
type: boolean
residentKey:
$ref: '#/components/schemas/ResidentKeyRequirement'
userVerification:
$ref: '#/components/schemas/UserVerificationRequirement'
GroupMember:
description: A User's membership into a Group
type: object
properties:
data:
type: object
additionalProperties:
type: object
groupId:
type: string
format: uuid
id:
type: string
format: uuid
insertInstant:
$ref: '#/components/schemas/ZonedDateTime'
userId:
type: string
format: uuid
PublicKeyCredentialDescriptor:
description: Contains attributes for the Relying Party to refer to an existing public key credential as an input parameter.
type: object
properties:
id:
type: string
transports:
type: array
items:
type: string
type:
$ref: '#/components/schemas/PublicKeyCredentialType'
UserTwoFactorConfiguration:
description: ''
type: object
properties:
methods:
type: array
items:
$ref: '#/components/schemas/TwoFactorMethod'
recoveryCodes:
type: array
items:
type: string
BreachedPasswordStatus:
description: ''
type: string
enum:
- None
- ExactMatch
- SubAddressMatch
- PasswordOnly
- CommonPassword
WebAuthnRegisterCompleteRequest:
description: Request to complete the WebAuthn registration ceremony for a new credential,.
type: object
properties:
credential:
$ref: '#/components/schemas/WebAuthnPublicKeyRegistrationRequest'
origin:
type: string
rpId:
type: string
userId:
type: string
format: uuid
AttestationConveyancePreference:
description: Used to communicate whether and how authenticator attestation should be delivered to the Relying Party
type: string
enum:
- none
- indirect
- direct
- enterprise
WebAuthnStartResponse:
description: API response for starting a WebAuthn authentication ceremony
type: object
properties:
options:
$ref: '#/components/schemas/PublicKeyCredentialRequestOptions'
AuthenticatorConfiguration:
description: ''
type: object
properties:
algorithm:
$ref: '#/components/schemas/TOTPAlgorithm'
codeLength:
type: integer
timeStep:
type: integer
PublicKeyCredentialParameters:
description: Supply information on credential type and algorithm to the authenticator.
type: object
properties:
alg:
$ref: '#/components/schemas/CoseAlgorithmIdentifier'
type:
$ref: '#/components/schemas/PublicKeyCredentialType'
WebAuthnPublicKeyRegistrationRequest:
description: Request to register a new public key with WebAuthn
type: object
properties:
clientExtensionResults:
$ref: '#/components/schemas/WebAuthnExtensionsClientOutputs'
id:
type: string
rpId:
type: string
response:
$ref: '#/components/schemas/WebAuthnAuthenticatorRegistrationResponse'
transports:
type: array
items:
type: string
type:
type: string
WebAuthnCredential:
description: A User's WebAuthnCredential. Contains all data required to complete WebAuthn authentication ceremonies.
type: object
properties:
algorithm:
$ref: '#/components/schemas/CoseAlgorithmIdentifier'
attestationType:
$ref: '#/components/schemas/AttestationType'
authenticatorSupportsUserVerification:
type: boolean
credentialId:
type: string
data:
type: object
additionalProperties:
type: object
discoverable:
type: boolean
displayName:
type: string
id:
type: string
format: uuid
insertInstant:
$ref: '#/components/schemas/ZonedDateTime'
lastUseInstant:
$ref: '#/components/schemas/ZonedDateTime'
name:
type: string
publicKey:
type: string
relyingPartyId:
type: string
signCount:
type: integer
tenantId:
type: string
format: uuid
transports:
type: array
items:
type: string
userAgent:
type: string
userId:
type: string
format: uuid
UserIdentity:
description: ''
type: object
properties:
displayValue:
type: string
insertInstant:
$ref: '#/components/schemas/ZonedDateTime'
lastLoginInstant:
$ref: '#/components/schemas/ZonedDateTime'
lastUpdateInstant:
$ref: '#/components/schemas/ZonedDateTime'
moderationStatus:
$ref: '#/components/schemas/ContentStatus'
primary:
type: boolean
type:
$ref: '#/components/schemas/IdentityType'
value:
type: string
verified:
type: boolean
verifiedInstant:
$ref: '#/components/schemas/ZonedDateTime'
verifiedReason:
$ref: '#/components/schemas/IdentityVerifiedReason'
PublicKeyCredentialRelyingPartyEntity:
description: Supply additional information about the Relying Party when creating a new credential
type: object
properties:
id:
type: string
name:
type: string
WebAuthnRegisterCompleteResponse:
description: API response for completing WebAuthn credential registration or assertion
type: object
properties:
credential:
$ref: '#/components/schemas/WebAuthnCredential'
WebAuthnRegistrationExtensionOptions:
description: Options to request extensions during credential registration
type: object
properties:
credProps:
type: boolean
PublicKeyCredentialType:
description: Defines valid credential types. This is an extension point in the WebAuthn spec. The only defined value at this time is "public-key"
type: string
enum:
- publicKey
Error:
description: Defines an error.
type: object
properties:
code:
type: string
data:
type: object
additionalProperties:
type: object
message:
type: string
CredentialPropertiesOutput:
description: Contains the output for the {@code credProps} extension
type: object
properties:
rk:
type: boolean
IdentityType:
description: Model identity types provided by FusionAuth.
type: object
properties:
name:
type: string
AttestationType:
description: Used to indicate what type of attestation was included in the authenticator response for a given WebAuthn credential at the time it was created
type: string
enum:
- basic
- self
- attestationCa
- anonymizationCa
- none
User:
description: The public, global view of a User. This object contains all global information about the user including birthdate, registration information preferred languages, global attributes, etc.
type: object
properties:
preferredLanguages:
type: array
items:
$ref: '#/components/schemas/Locale'
active:
type: boolean
birthDate:
$ref: '#/components/schemas/LocalDate'
cleanSpeakId:
type: string
format: uuid
data:
type: object
additionalProperties:
type: object
email:
type: string
expiry:
$ref: '#/components/schemas/ZonedDateTime'
firstName:
type: string
fullName:
type: string
imageUrl:
type: string
format: URI
insertInstant:
$ref: '#/components/schemas/ZonedDateTime'
lastName:
type: string
lastUpdateInstant:
$ref: '#/components/schemas/ZonedDateTime'
middleName:
type: string
mobilePhone:
type: string
parentEmail:
type: string
phoneNumber:
type: string
tenantId:
type: string
format: uuid
timezone:
$ref: '#/components/schemas/ZoneId'
twoFactor:
$ref: '#/components/schemas/UserTwoFactorConfiguration'
memberships:
type: array
items:
$ref: '#/components/schemas/GroupMember'
registrations:
type: array
items:
$ref: '#/components/schemas/UserRegistration'
identities:
type: array
items:
$ref: '#/components/schemas/UserIdentity'
breachedPasswordLastCheckedInstant:
$ref: '#/components/schemas/ZonedDateTime'
breachedPasswordStatus:
$ref: '#/components/schemas/BreachedPasswordStatus'
connectorId:
type: string
format: uuid
encryptionScheme:
type: string
factor:
type: integer
id:
type: string
format: uuid
lastLoginInstant:
$ref: '#/components/schemas/ZonedDateTime'
password:
type: string
passwordChangeReason:
$ref: '#/components/schemas/ChangePasswordReason'
passwordChangeRequired:
type: boolean
passwordLastUpdateInstant:
$ref: '#/components/schemas/ZonedDateTime'
salt:
type: string
uniqueUsername:
type: string
username:
type: string
usernameStatus:
$ref: '#/components/schemas/ContentStatus'
verified:
type: boolean
verifiedInstant:
$ref: '#/components/schemas/ZonedDateTime'
WebAuthnLoginRequest:
description: Request to complete the WebAuthn registration ceremony
type: object
properties:
credential:
$ref: '#/components/schemas/WebAuthnPublicKeyAuthenticationRequest'
origin:
type: string
rpId:
type: string
twoFactorTrustId:
type: string
applicationId:
type: string
format: uuid
ipAddress:
type: string
metaData:
$ref: '#/components/schemas/MetaData'
newDevice:
type: boolean
noJWT:
type: boolean
WebAuthnAuthenticatorAuthenticationResponse:
description: The authenticator's response for the authentication ceremony in its encoded format
type: object
properties:
authenticatorData:
type: string
clientDataJSON:
type: string
signature:
type: string
userHandle:
type: string
WebAuthnCredentialImportRequest:
description: API request to import an existing WebAuthn credential(s)
type: object
properties:
credentials:
type: array
items:
$ref: '#/components/schemas/WebAuthnCredential'
validateDbConstraints:
type: boolean
PublicKeyCredentialCreationOptions:
description: Allows the Relying Party to specify desired attributes of a new credential.
type: object
properties:
attestation:
$ref: '#/components/schemas/AttestationConveyancePreference'
authenticatorSelection:
$ref: '#/components/schemas/AuthenticatorSelectionCriteria'
challenge:
type: string
excludeCredentials:
type: array
items:
$ref: '#/components/schemas/PublicKeyCredentialDescriptor'
extensions:
$ref: '#/components/schemas/WebAuthnRegistrationExtensionOptions'
pubKeyCredParams:
type: array
items:
$ref: '#/components/schemas/PublicKeyCredentialParameters'
rp:
$ref: '#/components/schemas/PublicKeyCredentialRelyingPartyEntity'
timeout:
type: integer
format: int64
user:
$ref: '#/components/schemas/PublicKeyCredentialUserEntity'
LoginPreventedResponse:
description: The summary of the action that is preventing login to be returned on the login response.
type: object
properties:
actionId:
type: string
format: uuid
actionerUserId:
type: string
format: uuid
expiry:
$ref: '#/components/schemas/ZonedDateTime'
localizedName:
type: string
localizedOption:
type: string
localizedReason:
type: string
name:
type: string
option:
type: string
reason:
type: string
reasonCode:
type: string
WebAuthnExtensionsClientOutputs:
description: Contains extension output for requested extensions during a WebAuthn ceremony
type: object
properties:
credProps:
$ref: '#/components/schemas/CredentialPropertiesOutput'
AuthenticatorAttachment:
description: Describes the authenticator attachment modality.
type: string
enum:
- platform
- crossPlatform
WebAuthnRegisterStartResponse:
description: API response for starting a WebAuthn registration ceremony
type: object
properties:
options:
$ref: '#/components/schemas/PublicKeyCredentialCreationOptions'
PublicKeyCredentialRequestOptions:
description: Provides the authenticator with the data it needs to generate an assertion.
type: object
properties:
allowCredentials:
type: array
items:
$ref: '#/components/schemas/PublicKeyCredentialDescriptor'
challenge:
type: string
rpId:
type: string
timeout:
type: integer
format: int64
userVerification:
$ref: '#/components/schemas/UserVerificationRequirement'
CoseAlgorithmIdentifier:
description: A number identifying a cryptographic algorithm. Values should be registered with the IANA COSE Algorithms registry
type: string
enum:
- ES256
- ES384
- ES512
- RS256
- RS384
- RS512
- PS256
- PS384
- PS512
PublicKeyCredentialUserEntity:
description: Supply additional information about the user account when creating a new credential
type: object
properties:
displayName:
type: string
id:
type: string
name:
type: string
LocalDate:
description: A date without a time-zone in the ISO-8601 calendar system, such as 2007-12-03.
example: '2007-12-03'
pattern: ^[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]$
type: string
ZoneId:
description: Timezone Identifier
example: America/Denver
pattern: ^w+/w+$
type: string
WebAuthnWorkflow:
description: Identifies the WebAuthn workflow. This will affect the parameters used for credential creation and request based on the Tenant configuration.
type: string
enum:
- bootstrap
- general
- reauthentication
DeviceInfo:
description: ''
type: object
properties:
description:
type: string
lastAccessedAddress:
type: string
lastAccessedInstant:
$ref: '#/components/schemas/ZonedDateTime'
name:
type: string
type:
type: string
ChangePasswordReason:
description: ''
type: string
enum:
- Administrative
- Breached
- Expired
- Validation
TwoFactorMethod:
description: ''
type: object
properties:
authenticator:
$ref: '#/components/schemas/AuthenticatorConfiguration'
email:
type: string
id:
type: string
lastUsed:
type: boolean
method:
type: string
mobilePhone:
type: string
secret:
type: string
WebAuthnStartRequest:
description: API request to start a WebAuthn authentication ceremony
type: object
properties:
applicationId:
type: string
format: uuid
credentialId:
type: string
format: uuid
loginId:
type: string
loginIdTypes:
type: array
items:
type: string
state:
type: object
additionalProperties:
type: object
userId:
type: string
format: uuid
workflow:
$ref: '#/components/schemas/WebAuthnWorkflow'
LoginResponse:
description: ''
type: object
properties:
actions:
type: array
items:
$ref: '#/components/schemas/LoginPreventedResponse'
changePasswordId:
type: string
changePasswordReason:
$ref: '#/components/schemas/ChangePasswordReason'
configurableMethods:
type: array
items:
type: string
emailVerificationId:
type: string
identityVerificationId:
type: string
methods:
type: array
items:
$ref: '#/components/schemas/TwoFactorMethod'
pendingIdPLinkId:
type: string
refreshToken:
type: string
refreshTokenId:
type: string
format: uuid
registrationVerificationId:
type: string
state:
type: object
additionalProperties:
type: object
threatsDetected:
type: array
uniqueItems: true
items: {}
token:
type: string
tokenExpirationInstant:
$ref: '#/components/schemas/ZonedDateTime'
trustToken:
type: string
twoFactorId:
type: string
twoFactorTrustId:
type: string
user:
$ref: '#/components/schemas/User'
securitySchemes:
ApiKeyAuth:
type: apiKey
name: Authorization
in: header
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT