Browse the API reference

Passwordless Login Verify

post/v1/auth/passkeys/login/verify

Part of Auth.

Complete a passwordless login. A user-verified passkey assertion is two factors in one gesture.

Authentication

This operation does not require an API key.

Request body

Required, application/json.

FieldTypeDescription
assertionrequiredobject

WebAuthn assertion (browser JSON, opaque)

Example request

curl
curl -X POST "https://api.robosystems.ai/v1/auth/passkeys/login/verify" \
  -H "Content-Type: application/json" \
  -d '{
  "assertion": {}
}'

Responses

200 Successful Response

FieldTypeDescription
userrequiredobject

User information

orgoptionalobject

Organization information (personal org created automatically on registration)

messagerequiredstring

Success message

statusoptionalstring

Login flow state: authenticated (token present), or a passkey MFA step is required before a session is issued (mfa_token present)

One of: authenticated, mfa_required, mfa_enrollment_required

Default: authenticated

mfa_tokenoptionalstring

Short-lived token authorizing the MFA second step or forced enrollment; present only when status is not 'authenticated'

tokenoptionalstring

JWT authentication token (optional for cookie-based auth)

expires_inoptionalinteger

Token expiry time in seconds from now

refresh_thresholdoptionalinteger

Recommended refresh threshold in seconds before expiry

StatusMeaning
400Invalid request
401Verification failed
422Validation Error
429Rate limit exceeded
500Internal server error