openapi: 3.2.0 info: title: MyAccount Management App Authenticator API version: 2025.01.1 description: 'APIs for managing a user''s own emails, phones, profile, and app authenticators. > **Note:** The MyAccount API doesn''t support delegated authentication.' termsOfService: https://developer.okta.com/terms/ contact: name: Okta Developer Team url: https://developer.okta.com/ email: devex-public@okta.com license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html x-logo: url: logo.svg backgroundColor: transparent altText: Okta Developer servers: - url: https://{yourOktaDomain} variables: yourOktaDomain: default: subdomain.okta.com description: The domain of your organization. This can be an official Okta domain (for example, `okta.com` or `oktapreview.com`) or one of your configured custom domains. tags: - name: AppAuthenticator x-displayName: App Authenticators description: 'The MyAccount App Authenticators API provides operations to enroll, update, and delete an app authenticator. The API also allows users to view and verify pending notification challenges. The API only supports custom authenticators. See the Custom authenticator integration guide. ### API versioning A valid API version in the `Accept` header is required to access the API. Current version: `1.0.0` ```json Accept: application/json; okta-version=1.0.0 ```' x-okta-lifecycle: lifecycle: GA isGenerallyAvailable: false SKUs: [] paths: /idp/myaccount/app-authenticators: post: summary: Create an App Authenticator Enrollment description: Creates an app authenticator enrollment operationId: createAppAuthenticatorEnrollment requestBody: content: application/json, okta-version=1.0.0: schema: $ref: '#/components/schemas/AppAuthenticatorEnrollmentRequest' examples: Create-App-Authenticator-Enrollment: $ref: '#/components/examples/CreateAppAuthenticatorEnrollment' responses: '200': description: OK content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/AppAuthenticatorEnrollment' '400': description: Bad Request content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '403': description: Access Denied content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '404': description: Resource Not Found content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' security: - oauth2: - okta.myAccount.appAuthenticator.manage tags: - AppAuthenticator x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine /idp/myaccount/app-authenticators/challenge/{challengeId}/verify: x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine parameters: - $ref: '#/components/parameters/appAuthenticatorChallengeId' post: summary: Verify a Push Notification Challenge Response from the App Authenticator description: Verifies a push notification challenge from the app authenticator operationId: verifyAppAuthenticatorPushNotificationChallenge requestBody: content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/PushNotificationVerification' examples: PushNotificationChallengeRequestEx: $ref: '#/components/examples/VerifyPushNotificationChallengeRequest' PushNotificationChallengeRequestJWTHeaderEx: $ref: '#/components/examples/VerifyPushNotificationChallengeJWTHeader' PushNotificationChallengeRequestJWTPayloadEx: $ref: '#/components/examples/VerifyPushNotificationChallengeJWTPayload' responses: '200': description: Verification Success '204': description: User denied challenge attempt '400': description: Bad Request security: [] tags: - AppAuthenticator /idp/myaccount/app-authenticators/{enrollmentId}: parameters: - $ref: '#/components/parameters/appAuthenticatorEnrollmentId' patch: summary: Update an App Authenticator Enrollment description: 'Updates an app authenticator enrollment The following update operations are allowed: * Update the user verification key * Remove the user verification key * Update the push token * Update the push method transaction types For more information, see Access token management in the Custom authenticator integration guide. > **Note:** The following higher risk update operations require a stronger `okta.myAccount.appAuthenticator.manage` scope: > * Update the user verification key > * Remove the user verification key' operationId: updateAppAuthenticatorEnrollment requestBody: content: application/merge-patch+json;okta-version=1.0.0: schema: $ref: '#/components/schemas/UpdateAppAuthenticatorEnrollmentRequest' examples: UpdateAppAuthenticatorEnrollmentPushTokenEx: $ref: '#/components/examples/UpdateAppAuthenticatorEnrollmentPushToken' EnrollAppAuthenticatorEnrollmentUserVerificationKeyEx: $ref: '#/components/examples/UpdateAppAuthenticatorEnrollmentUserVerificationKey' UnenrollAppAuthenticatorEnrollmentUserVerificationKeyEx: $ref: '#/components/examples/UnenrollAppAuthenticatorEnrollmentUserVerificationKey' UpdateAppAuthenticatorEnrollmentTransactionTypeEx: $ref: '#/components/examples/UpdateAppAuthenticatorEnrollmentTransactionType' UpdateAppAuthenticatorEnrollmentPushTokenandEnrollUserVerificationKeyEx: $ref: '#/components/examples/UpdateAppAuthenticatorEnrollmentPushTokenAndUserVerificationKey' responses: '200': description: OK content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/AppAuthenticatorEnrollment' '401': description: Unauthorized content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '403': description: Access Denied content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '404': description: Resource Not Found content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' security: - oauth2: - okta.myAccount.appAuthenticator.maintenance.manage tags: - AppAuthenticator x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine delete: summary: Delete an App Authenticator Enrollment description: Deletes an app authenticator enrollment operationId: deleteAppAuthenticatorEnrollment responses: '204': description: No Content '401': description: Unauthorized content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '403': description: Access Denied content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' '404': description: Resource Not Found content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' security: - oauth2: - okta.myAccount.appAuthenticator.manage tags: - AppAuthenticator x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine /idp/myaccount/app-authenticators/{enrollmentId}/push/notifications: parameters: - $ref: '#/components/parameters/appAuthenticatorEnrollmentId' get: summary: List all pending Push Notification Challenges description: Lists all pending push notification challenges operationId: listAppAuthenticatorPendingPushNotificationChallenges responses: '200': description: Success content: application/json;okta-version=1.0.0: schema: type: array items: $ref: '#/components/schemas/PushNotificationChallenge' examples: SuccessResponseEx: $ref: '#/components/examples/GetPendingNotificationsSuccessResponse' JWTHeaderEx: $ref: '#/components/examples/GetPendingNotificationsJWTHeader' JWTPayloadEx: $ref: '#/components/examples/GetPendingNotificationsJWTPayload' '401': $ref: '#/components/responses/Error-IdpMyAccountNotEnabled-Response-401' security: - oauth2: - okta.myAccount.appAuthenticator.maintenance.read tags: - AppAuthenticator x-okta-lifecycle: lifecycle: LIMITED_GA isGenerallyAvailable: false SKUs: - Okta Identity Engine components: responses: Error-IdpMyAccountNotEnabled-Response-401: description: Unauthorized content: application/json;okta-version=1.0.0: schema: $ref: '#/components/schemas/Error' examples: IDP-MyAccount-not-enabled-401: value: errorCode: E0000015 errorSummary: You do not have permission to access the feature you are requesting errorLink: E0000015 errorId: oaeStOuPPxDRUm3PJhf-tL7bQ errorCauses: [] schemas: PushNotificationChallenge: description: Push notification challenge request object for an app authenticator type: object properties: challenge: type: string description: 'JWT issued by Okta at the time of challenging for a push notification. This based64-encoded JWT consists of a [JWT header](/openapi/okta-myaccount/myaccount/tag/AppAuthenticator/#tag/AppAuthenticator/schema/PushNotificationChallengeRequestJwtHeader) and a [JWT payload](/openapi/okta-myaccount/myaccount/tag/AppAuthenticator/#tag/AppAuthenticator/schema/PushNotificationChallengeRequestJwt). ' payloadVersion: type: string enum: - IDXv1 AppAuthenticatorMethodCapabilities: type: object properties: transactionTypes: type: array items: type: string enum: - LOGIN - CIBA UpdateAppAuthenticatorEnrollmentRequest: type: object properties: methods: type: object properties: push: type: object properties: pushToken: type: string keys: type: object properties: userVerification: $ref: '#/components/schemas/KeyObject' capabilities: type: object $ref: '#/components/schemas/AppAuthenticatorMethodCapabilities' PushNotificationVerification: description: Push notification challenge response object for an app authenticator type: object properties: challengeResponse: type: string description: 'JWT issued by the app authenticator at the time of push notification verification This based64-encoded JWT consists of a [JWT header](/openapi/okta-myaccount/myaccount/tag/AppAuthenticator/#tag/AppAuthenticator/schema/PushNotificationChallengeResponseJwtHeader) and a [JWT payload](/openapi/okta-myaccount/myaccount/tag/AppAuthenticator/#tag/AppAuthenticator/schema/PushNotificationChallengeResponseJwt). ' method: type: string enum: - push KeyObject: oneOf: - $ref: '#/components/schemas/KeyEC' - $ref: '#/components/schemas/KeyRSA' type: object Error: description: Standard API error object type: object properties: errorCauses: type: array description: (Optional) Further information about what caused this error items: type: object properties: errorSummary: type: string description: A natural language explanation of the error example: Bad request because XYZ is missing. readOnly: true errorCode: type: string description: A code that is associated with this error type example: E0000001 readOnly: true errorId: type: string description: A unique identifier for this error. This can be used by Okta Support to help with troubleshooting. example: oaeWGQKoQHeQmy0u8w8bPwi_Q readOnly: true errorLink: type: string description: A link to documentation with a more detailed explanation of the error (not yet implemented and is currently the same value as the 'errorCode') example: E0000001 readOnly: true errorSummary: type: string description: A natural language explanation of the error example: Bad request because XYZ is missing. readOnly: true KeyEC: type: object properties: crv: type: string enum: - P-256 kid: type: string description: The unique identifier of the key kty: type: string enum: - EC description: The type of public key okta:kpr: type: string enum: - HARDWARE - SOFTWARE x: type: string description: The public x coordinate for the elliptic curve point y: type: string description: The public y coordinate for the elliptic curve point required: - x - y - kty - okta:kpr - crv - kid AppAuthenticatorEnrollment: description: App authenticator enrollment object type: object properties: authenticatorId: type: string readOnly: true createdDate: type: string format: date-time readOnly: true device: type: object properties: id: type: string status: type: string enum: - ACTIVE createdDate: type: string format: date-time lastUpdated: type: string format: date-time clientInstanceId: type: string readOnly: true id: type: string readOnly: true lastUpdated: type: string format: date-time readOnly: true links: type: object description: Discoverable resources related to the app authenticator properties: self: type: object description: Link to the resource (app authenticator) properties: href: type: string description: Link URI minLength: 1 hints: type: object description: Describes the allowed HTTP verbs for the `href` properties: allow: type: array items: type: string enum: - PATCH - DELETE readOnly: true methods: type: object properties: push: type: object properties: id: type: string createdDate: type: string format: date-time lastUpdated: type: string format: date-time links: type: object properties: pending: type: object properties: href: type: string minLength: 1 hints: type: object properties: allow: type: array items: type: string enum: - GET user: type: object properties: id: type: string username: type: string readOnly: true KeyRSA: type: object properties: e: type: string description: The key exponent of a RSA key kid: type: string description: The unique identifier of the key kty: type: string enum: - RSA description: The type of public key n: type: string description: The modulus of the RSA key okta:kpr: type: string enum: - HARDWARE - SOFTWARE required: - n - e - kty - okta:kpr - kid AppAuthenticatorEnrollmentRequest: description: App authenticator enrollment request type: object properties: authenticatorId: type: string device: type: object properties: secureHardwarePresent: type: boolean description: Indicates if the device is equipped with TPM storage for storing signing keys clientInstanceKey: $ref: '#/components/schemas/KeyObject' description: A public key in Json Web Keys format that is not tied to a user. It can be used to identify a device across orgs. osVersion: type: string clientInstanceBundleId: type: string platform: type: string enum: - ANDROID - IOS manufacturer: type: string example: - APPLE - Google deviceAttestation: type: object clientInstanceVersion: type: string clientInstanceDeviceSdkVersion: type: string model: type: string example: - iPhone 14 - Pixel 4 displayName: type: string description: The device's display name udid: type: string required: - clientInstanceKey - clientInstanceBundleId - clientInstanceVersion - clientInstanceDeviceSdkVersion - osVersion - platform - displayName methods: type: object required: - push properties: push: type: object required: - pushToken - keys properties: apsEnvironment: type: string description: Target APS type that application registers to. Required for iOS enrollments. enum: - PRODUCTION - DEVELOPMENT pushToken: type: string keys: type: object required: - proofOfPossession properties: proofOfPossession: $ref: '#/components/schemas/KeyObject' userVerification: $ref: '#/components/schemas/KeyObject' capabilities: $ref: '#/components/schemas/AppAuthenticatorMethodCapabilities' required: - authenticatorId - device - methods examples: UpdateAppAuthenticatorEnrollmentPushToken: summary: Update app authenticator enrollment push token value: methods: push: pushToken: 667b713e90871f014805f45f770c90d161b84b609d167039b2c388c7bacfdaa1 UnenrollAppAuthenticatorEnrollmentUserVerificationKey: summary: Unenroll app authenticator enrollment user verification key value: methods: push: keys: userVerification: null VerifyPushNotificationChallengeRequest: summary: Push notification challenge request value: method: push challengeResponse: Your encoded challenge response JWT GetPendingNotificationsJWTPayload: summary: JWT Payload value: - iss: https://{{yourOktaDomain}} aud: okta.63c081db-1f13-5084-882f-e79e1e5e2da7 exp: 1648339796 iat: 1648339496 jti: ft-hqOpHM8yxcGvE0cN7UXWVodVyP0omKW nonce: LA_OIcYdr4R0GqMDJ08p transactionId: ft-hqOpHM8yxcGvE0cN7UXWVodVyP0omKW signals: - id - displayName - platform - manufacturer - model - osVersion - serialNumber - udid - sid - imei - meid - secureHardwarePresent - deviceAttestation verificationUri: https://{{yourOktaDomain}}/idp/myaccount/app-authenticators/challenge/ft-hqOpHM8yxcGvE0cN7UXWVodVyP0omKW/verify orgId: 00o54bswOJKhBhzy20w5 appInstanceName: Okta Dashboard method: push methodEnrollmentId: opf6aeq9U2hoM8aqO0w5 authorizationServerId: aus1k3lsbNOta5rds0g5 userMediation: REQUIRED userVerification: PREFERRED authenticatorEnrollmentId": pfd7rzcmvlhmE0Y1w0g4 challengeContext: clientOS: MAC_OS_X clientLocation: San Francisco, California, United States transactionTime: '2022-03-27T00:04:56.861Z' transactionType: LOGIN bindingMessage: Required if transactionType = CIBA userId: 00u44bx5BuSpiLUMl0w5 ver: 0 UpdateAppAuthenticatorEnrollmentUserVerificationKey: summary: Enroll app authenticator enrollment user verification key value: methods: push: keys: userVerification: x: V0p-5JFpcen4Iep94ihs00Kjezw9sblfMSUW-cJxTRk y: wgJ9SFT3iaT6cqS08TBIBg_K-20r_4FMGFUlN2BXFJc kty: EC okta:kpr: HARDWARE crv: P-256 kid: 80D6AC7B-B640-4899-A32C-CA7B98BE0AE6 UpdateAppAuthenticatorEnrollmentTransactionType: summary: Update app authenticator enrollment transaction type value: methods: push: capabilities: transactionTypes: - LOGIN - CIBA VerifyPushNotificationChallengeJWTPayload: summary: JWT Payload value: iss: pfd7rzcmvlhmE0Y1w0g4 sub: 00u12xkg3YOQqFyeC0g6 aud: https://{{yourOktaDomain}} jti: 9866e66d-e173-487a-878b-4059ffb15255 iat: 1648687225 exp: 1648687525 nbf: 1648686925 methodEnrollmentId: opf13zf81eK3VfeHE0g6 tx: ftxWtAah8d4Gv-P-ZcMdbSmELeRlRShWNR nonce: 4OvrzlCotGBJIVCAzHb9 deviceSignals: id: guo13zf7vXryjyUCU0g6 isHardwareProtectionEnabled: false, model: Pixel 4 manufacturer: Google displayName: Pixel 4 platform": ANDROID osVersion": 12:2022-03-05 clientInstanceId": cli13zf7wfZ27xCRQ0g6 clientInstanceBundleId: com.okta.devices.push.app clientInstanceVersion: 1 secureHardwarePresent: true screenLockType: BIOMETRIC diskEncryptionType: USER keyType: proofOfPossession challengeResponseContext: userConsent: APPROVED_CONSENT_PROMPT transactionType: LOGIN CreateAppAuthenticatorEnrollment: summary: Create app authenticator enrollment value: authenticatorId: aut12i8bdXk90NIfr0q5 device: secureHardwarePresent: true clientInstanceKey: x: O0N1H3AIXj5p5cpQx5RUzowIRz1iPnheo7SbEC-CtFw y: Cea3KAFqsyxqPni2QJ6LjjqgRKgRHpsVzkNazd3m8To kty: EC okta:kpr: HARDWARE crv: P-256 kid: DF47DEE2-D1B0-40B6-BEB7-09134CC4A19B osVersion: '14.3' clientInstanceBundleId: com.company.authenticatorApp platform: IOS manufacturer: APPLE deviceAttestation: {} clientInstanceVersion: 6.4.0 clientInstanceDeviceSdkVersion: DeviceSDK 1.0.0 model: iPhone displayName: My device name udid: 4956095A-D99E-4A4E-A6DC-9E63E5978722 methods: push: apsEnvironment: DEVELOPMENT pushToken: 667b773e90871f014805f45f770c90d161b84b609d167039b2c388c7bacfdaa1 keys: proofOfPossession: x: hFr-xcGSMHbWKq2_SUAOMkif1ARYAU-X_8ZGprOhxfw y: HVqAxDCiGcV7H0QAQas6CMbh2wyG-cPU_cwXv3kPqcI kty: EC okta:kpr: HARDWARE crv: P-256 kid: 2078892D-BC96-4C8C-A3FA-34045C002C4A userVerification: x: V0p-5JFpcen4Iep94ihs00Kjezw9sblfMSUW-cJxTRk y: wgJ9SFT3iaT6cqS08TBIBg_K-20r_4FMGFUlN2BXFJc kty: EC okta:kpr: HARDWARE crv: P-256 kid: 80D6AC7B-B640-4899-A32C-CA7B98BE0AE6 capabilities: transactionTypes: - LOGIN - CIBA VerifyPushNotificationChallengeJWTHeader: summary: JWT Header value: typ: okta-pushbind+jwt kid: b33b262d-b054-4519-833e-0893f53616ec alg: RS256 GetPendingNotificationsJWTHeader: summary: JWT Header value: - kid: seD0hUMrcpFtlVVTmkDyJ0mGxlEygWEZ42ts9z4ih9M typ: okta-pushbind+jwt alg: RS256 UpdateAppAuthenticatorEnrollmentPushTokenAndUserVerificationKey: summary: Update app authenticator enrollment push token and enroll user verification key value: methods: push: pushToken: 667b713e90871f014805f45f770c90d161b84b609d167039b2c388c7bacfdaa1 keys: userVerification: x: V0p-5JFpcen4Iep94ihs00Kjezw9sblfMSUW-cJxTRk y: wgJ9SFT3iaT6cqS08TBIBg_K-20r_4FMGFUlN2BXFJc kty: EC okta:kpr: HARDWARE crv: P-256 kid: 80D6AC7B-B640-4899-A32C-CA7B98BE0AE6 GetPendingNotificationsSuccessResponse: summary: Success response value: - payloadVersion: IDXv1 challenge: Your encoded challenge request JWT parameters: appAuthenticatorChallengeId: name: challengeId in: path required: true description: Id of the challenge associated with the app authenticator schema: type: string example: ft-hqOpHM8yxcGvE0cN7UXWVodVyP0omKW appAuthenticatorEnrollmentId: name: enrollmentId in: path required: true description: Id of the user's app authenticator enrollment schema: type: string example: pfd7rzcmvlhmE0Y1w0g4 securitySchemes: oauth2: type: oauth2 description: 'Pass the access_token as the value of the Authorization header: `Authorization: Bearer {access_token}`' flows: authorizationCode: authorizationUrl: /oauth2/v1/authorize tokenUrl: /oauth2/v1/token scopes: okta.myAccount.appAuthenticator.maintenance.manage: Write access to non-sensitive attributes of user app authenticator enrollments okta.myAccount.appAuthenticator.maintenance.read: Read access to non-sensitive attributes of user app authenticator enrollments okta.myAccount.appAuthenticator.manage: Write access to user app authenticator enrollments okta.myAccount.appAuthenticator.read: Read access to user app authenticator enrollments okta.myAccount.authenticators.manage: Write access to user authenticator enrollments okta.myAccount.authenticators.read: Read access to user authenticator configurations and enrollments okta.myAccount.email.manage: Write access to user emails okta.myAccount.email.read: Read access to user emails okta.myAccount.oktaApplications.read: Read access to the Okta apps list okta.myAccount.organization.read: Read access to org details okta.myAccount.password.manage: Write access to user password okta.myAccount.password.read: Read access to user password metadata okta.myAccount.phone.manage: Write access to user phones okta.myAccount.phone.read: Read access to user phones okta.myAccount.profile.manage: Write access to user profile and schema okta.myAccount.profile.read: Read access to user profile and schema okta.myAccount.sessions.manage: Write access to user sessions externalDocs: description: Find more info here url: https://developer.okta.com