Request a passkey login challenge.
Step 1 of the granular login flow. Returns the auth session and a
decoded PublicKeyCredentialRequestOptions. Run the WebAuthn assertion
ceremony with publicKey, then hand the resulting credential and authSession to
getTokenWithPasskey().
Optional options: PasskeyLoginChallengeOptionsOptional login challenge options (realm/organization)
A promise resolving to { authSession, publicKey }
If WebAuthn is not supported in the browser
If the challenge request fails
Request a passkey signup challenge.
Step 1 of the granular signup flow. Returns the auth session and a
decoded PublicKeyCredentialCreationOptions. Run the WebAuthn credential
creation ceremony with publicKey, then hand the resulting credential and authSession to
getTokenWithPasskey().
Signup challenge options (user identifier, optional realm/organization/metadata)
A promise resolving to { authSession, publicKey }
If WebAuthn is not supported in the browser
If the challenge request fails
Exchange a signed passkey credential for tokens.
Step 2 of the granular flow. Serializes the raw PublicKeyCredential
produced by the WebAuthn ceremony — either a creation (signup) or an
assertion (login) credential — and exchanges it for tokens. The credential
type (attestation vs assertion) is detected automatically.
The auth session, raw credential, and optional realm/organization/scope/audience
A promise resolving to the token endpoint response
If WebAuthn is not supported in the browser
If the credential is not a valid attestation or assertion response
If the token exchange fails
Sign in with an existing passkey.
Handles the full flow: requests a login challenge, triggers the browser WebAuthn assertion ceremony, serializes the result, and exchanges it for tokens.
Optional options: PasskeyLoginOptionsOptional passkey login options (optional scope/audience/realm/organization)
A promise that resolves to the token endpoint response containing access/ID tokens
If WebAuthn is not supported in the browser
If the challenge request fails
If the token exchange fails
If the user cancels the WebAuthn prompt
Register a new user with a passkey.
Handles the full flow: requests a signup challenge, triggers the browser WebAuthn credential creation ceremony, serializes the result, and exchanges it for tokens.
Passkey signup options (user identifier, optional scope/audience)
A promise that resolves to the token endpoint response containing access/ID tokens
If WebAuthn is not supported in the browser
If the challenge request fails
If the token exchange fails
If the user cancels the WebAuthn prompt
Client for Auth0 Passkey operations.
Provides 2 public methods:
signup— Register a new user with a passkey (full flow: challenge → WebAuthn → token exchange)login— Sign in with a passkey (full flow: challenge → WebAuthn → token exchange)Example