Complete Passkey Login
Verifies a WebAuthn assertion, resolves the org-account user (asserting it belongs to the request org), and mints the portal token. A passkey satisfies MFA, so no step-up is required.
Authentication: None required (session id required)
Authorization
BearerAuth JWT access token for internal API access. Requires 'private' scope for most endpoints, 'admin' scope for administrative operations.
In: header
Header Parameters
Define the version of the Connect protocol
1Define the timeout, in ms
Request Body
application/json
The navigator.credentials.get() assertion, serialized as JSON.
1 <= lengthThe session id from PasskeyLoginBeginResponse.
1 <= length <= 255Response Body
application/json
application/json
curl -X POST "https://auth.xeonr.io/xeonr.auth.private.v1.AuthService/PasskeyLoginFinish" \ -H "Connect-Protocol-Version: 1" \ -H "Content-Type: application/json" \ -d '{}'{
"token": "string",
"expiresAt": "2023-01-15T01:30:15.01Z",
"sessionToken": "string"
}{
"code": "not_found",
"message": "string",
"details": [
{
"type": "string",
"value": "string",
"debug": {}
}
]
}Begin Passkey Login POST
Starts a WebAuthn passkey login: returns PublicKeyCredentialRequestOptions for a discoverable (usernameless) assertion plus a session id. The org is taken from the X-Xeonr-Auth-Org-Id header and the RP ID is derived from its domain. **Authentication:** None required
Refresh Session POST
Exchanges a long-lived session token for a fresh short-lived access token, sliding the session's expiry. Lets IdP/social and just-signed-up users keep a long persistent session without re-authenticating, mirroring the password 'remember me' flow. **Authentication:** None required (session token required)