openapi: 3.2.0 info: title: Janssen Fido2 FIDO2 Attestation API description: Janssen Fido2 - FIDO 2.0 is an open authentication standard that enables leveraging common devices to authenticate to online services in both mobile and desktop environments. contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io tags: - name: FIDO2 Attestation paths: /jans-fido2/restv1/attestation/options: post: tags: - FIDO2 Attestation summary: Create new registration description: Create new registration. operationId: attestation-options requestBody: content: application/json: schema: title: AttestationOptions description: An object containing various options for the option creation type: object required: - username - displayName - attestation properties: username: type: string displayName: type: string attestation: type: string format: enum - direct - indirect - none documentDomain: type: string timeout: type: integer extensions: type: object authenticatorSelection: type: object properties: authenticatorAttachment: type: string format: enum - platform - cross-platform userVerification: type: string format: enum - direct - indirect - none requireResidentKey: type: boolean responses: 200: description: OK content: application/json: schema: title: CredentialCreationOptions type: object properties: attestation: type: string format: enum - direct - indirect - none authenticatorSelection: type: object properties: authenticatorAttachment: type: string format: enum - platform - cross-platform userVerification: type: string format: enum - required - preferred - discouraged requireResidentKey: type: boolean challenge: type: string description: The base64url encoded challenge that was sent to the client, as generated by assertionOptions. pubKeyCredParams: type: object properties: type: type: string alg: type: string rp: type: object description: RP credentials properties: name: type: string id: type: string username: type: string displayName: type: string user: type: object description: User object properties: id: type: string name: type: string displayName: type: string excludeCredentials: type: object properties: type: type: string id: type: string timeout: type: integer extensions: type: array items: type: string status: type: string errorMessage: type: string 403: $ref: '#/components/responses/AccessDenied' 500: $ref: '#/components/responses/InternalServerError' /jans-fido2/restv1/attestation/result: post: tags: - FIDO2 Attestation summary: FIDO2 attestation result operationId: attestation-result requestBody: content: application/json: schema: title: AttestationOptions description: An object containing various options for the option creation type: object required: - id - type - response properties: id: type: string description: base64url encoded type: type: string enum: - public-key response: type: object required: - clientDataJSON - attestationObject properties: attestationObject: type: string description: base64url encoded clientDataJSON: type: object description: The base64url encoded clientDataJSON returned by the client required: - challenge - origin - type properties: type: type: string enum: - webauthn.create origin: type: string challenge: type: string tokenBinding: type: object required: - status properties: status: type: string id: type: string clientExtensionResults: type: array items: type: string responses: 200: description: OK content: application/json: schema: title: Fido2RegistrationData type: object properties: createdCredentials: type: object properties: createdDate: type: string format: date-time updatedDate: type: string format: date-time createdBy: type: string updatedBy: type: string username: type: string domain: type: string userId: type: string challenge: type: string attestationRequest: type: string attestationResponse: type: object properties: type: type: string enum: - public-key id: type: string response: type: object required: - attestationObject - clientDataJSON properties: attestationObject: type: string clientDataJSON: type: string clientExtensionResults: type: array items: type: string uncompressedECPoint: type: string publicKeyId: type: string type: type: string enum: - public-key status: type: string enum: - registered counter: type: integer attestationType: type: string signatureAlgorithm: type: integer applicationId: type: string authenticatorSelection: type: object properties: authenticatorAttachment: type: string format: enum - platform - cross-platform userVerification: type: string format: enum - required - preferred - discouraged requireResidentKey: type: boolean errorMessage: type: string status: type: string 403: $ref: '#/components/responses/AccessDenied' 500: $ref: '#/components/responses/InternalServerError' components: responses: AccessDenied: description: Invalid details provided hence access denied. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' InternalServerError: description: Internal error occured. Please check log file for details. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' schemas: ErrorResponse: required: - error - error_description type: object properties: error: type: string error_description: type: string details: type: string