openapi: 3.2.0 info: title: Janssen Fido2 FIDO2 Assertion API description: Janssen Fido2 - FIDO 2.0 is an open authentication standard that enables leveraging common devices to authenticate to online services in both mobile and desktop environments. contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io tags: - name: FIDO2 Assertion paths: /jans-fido2/restv1/assertion/options: post: tags: - FIDO2 Assertion summary: FIDO2 Assertion Options operationId: options requestBody: content: application/json: schema: title: AssertionOptions description: An object that contains the extensions to enable, and the options to use for each of them. type: object required: - username properties: username: type: string userVerification: type: string documentDomain: type: string extensions: type: string session_id: type: string responses: 200: description: OK content: application/json: schema: title: AssertionOptionsResponse type: object required: - challenge - user - allowCredentials - userVerification - extensions properties: challenge: type: string description: Websafe-base64 encoding of the challenge. user: type: string description: username allowCredentials: type: array items: type: string example: - type - transports - id userVerification: type: string extensions: type: object rpId: type: string description: Document domain. status: type: string errorMessage: type: string 403: $ref: '#/components/responses/AccessDenied' 500: $ref: '#/components/responses/InternalServerError' /jans-fido2/restv1/assertion/result: post: tags: - FIDO2 Assertion summary: FIDO2 Assertion Result - Parses and validates an assertion response from the… description: FIDO2 Assertion Result. operationId: result requestBody: content: application/json: schema: title: AssertionOptions type: object required: - id - type - response - rawId properties: id: type: string description: The base64url encoded id type: type: string example: - public-key rawId: type: string description: The base64url encoded rawId returned by the client. If res.rawId is missing, res.id will be used instead. If both are missing an error will be thrown. response: type: object properties: userHandle: type: string description: The base64url encoded userHandle returned by the client. May be null or an empty string. clientDataJSON: type: string description: The base64url encoded clientDataJSON returned by the client. authenticatorData: type: string description: The base64url encoded authenticator Data. May be null or an empty string. signature: type: string description: To verify signature. responses: 200: description: OK content: application/json: schema: title: AssertionVerifyResponse type: object required: - status properties: status: type: string errorMessage: type: string authenticatedCredentials: type: object properties: type: type: string id: type: string transports: type: array description: list of transports. items: type: string example: - net - qr - usb 403: $ref: '#/components/responses/AccessDenied' 500: $ref: '#/components/responses/InternalServerError' components: responses: AccessDenied: description: Invalid details provided hence access denied. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' InternalServerError: description: Internal error occured. Please check log file for details. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' schemas: ErrorResponse: required: - error - error_description type: object properties: error: type: string error_description: type: string details: type: string