diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx
index e2a857e30..2d0341163 100644
--- a/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx
+++ b/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx
@@ -57,9 +57,7 @@ all options; an empty list disables the check.
```json
{
- "delete": {
- "client_key_id": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c"
- },
+ "deviceauthn_remove": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c",
"method": "deviceauthn"
}
```
@@ -74,8 +72,7 @@ all options; an empty list disables the check.
val body = UpdateSettingsFlowBody()
val method = UpdateSettingsFlowWithDeviceAuthnMethod()
method.method = "deviceauthn"
- method.delete = UpdateSettingsFlowWithDeviceAuthnMethodDelete()
- method.delete!!.clientKeyId = clientKeyIdToDelete
+ method.deviceauthnRemove = clientKeyIdToDelete
body.actualInstance = method
val updatedFlow = apiInstance.updateSettingsFlow(settingsFlow?.id, body, sessionToken, "")
```
@@ -90,8 +87,9 @@ all options; an empty list disables the check.
```json
{
"method": "deviceauthn",
- "add": {
+ "deviceauthn_register": {
"device_name": "Pixel 9",
+ "version": 1,
"certificate_chain_android": ["...", "...", "..."]
}
}
@@ -113,9 +111,10 @@ all options; an empty list disables the check.
val body = UpdateSettingsFlowBody()
val method = UpdateSettingsFlowWithDeviceAuthnMethod()
method.method = "deviceauthn"
- method.add = UpdateSettingsFlowWithDeviceAuthnMethodAdd()
- method.add!!.deviceName = "My work phone"
- method.add!!.certificateChainAndroid = keyCertChain.map { it.encoded }.toList()
+ method.deviceauthnRegister = UpdateSettingsFlowWithDeviceAuthnMethodRegister()
+ method.deviceauthnRegister!!.deviceName = "My work phone"
+ method.deviceauthnRegister!!.version = 1
+ method.deviceauthnRegister!!.certificateChainAndroid = keyCertChain.map { it.encoded }.toList()
body.actualInstance = method
val updatedFlow = apiInstance.updateSettingsFlow(settingsFlow?.id, body, sessionToken, "")
@@ -701,10 +700,10 @@ discipline when you wire these calls.
1. **Enroll** (PIN enrollment) —
`decodeNonce` the flow's `deviceauthn_nonce` node, `createSealingKey`, create a `PinCeremony`, then
- `createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `add` payload with `transport_public_key` and the
- returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the `continue_with` item, derive the
- fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony`
- go out of scope so its transport key is destroyed.
+ `createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `deviceauthn_register` payload with
+ `transport_public_key` and the returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the
+ `continue_with` item, derive the fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the
+ `PinArtifacts`. Let the `PinCeremony` go out of scope so its transport key is destroyed.
2. **Log in** (First-factor
login) — `decodeNonce`, `PinVault.unseal` with the entered PIN, `pinProof(pinSecret, clientKeyId, nonce)`,
and `sign(alias, nonce)` over the raw nonce, then submit `client_key_id`, `signature`, and `pin_proof`.
diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx
index 7e2b4e324..8b73b8525 100644
--- a/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx
+++ b/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx
@@ -275,7 +275,7 @@ Runs in a settings flow under a privileged session.
```json
{
"method": "deviceauthn",
- "add": {
+ "deviceauthn_register": {
"device_name": "My work phone",
"version": 1,
"pin_protected": true,
diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx
index e78e2e95b..00c9bcaac 100644
--- a/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx
+++ b/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx
@@ -67,9 +67,7 @@ all options; an empty list disables the check.
```json
{
- "delete": {
- "client_key_id": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c"
- },
+ "deviceauthn_remove": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c",
"method": "deviceauthn"
}
```
@@ -86,9 +84,7 @@ all options; an empty list disables the check.
let body: UpdateSettingsFlowBody =
.typeUpdateSettingsFlowWithDeviceAuthnMethod(
UpdateSettingsFlowWithDeviceAuthnMethod(
- delete: UpdateSettingsFlowWithDeviceAuthnMethodDelete(
- clientKeyId: clientKeyId,
- ),
+ deviceauthnRemove: clientKeyId,
method: "deviceauthn"
)
)
@@ -109,8 +105,9 @@ all options; an empty list disables the check.
```json
{
"method": "deviceauthn",
- "add": {
+ "deviceauthn_register": {
"device_name": "iPhone (iPhone14,5)",
+ "version": 1,
"attestation_ios": "..."
}
}
@@ -132,9 +129,10 @@ all options; an empty list disables the check.
let body: UpdateSettingsFlowBody =
.typeUpdateSettingsFlowWithDeviceAuthnMethod(
UpdateSettingsFlowWithDeviceAuthnMethod(
- add: UpdateSettingsFlowWithDeviceAuthnMethodAdd(
+ deviceauthnRegister: UpdateSettingsFlowWithDeviceAuthnMethodRegister(
attestationIos: attestation,
deviceName: deviceName,
+ version: 1,
),
method: "deviceauthn"
)
@@ -585,9 +583,9 @@ func loginWithPin(flowNonce: Data, pin: inout [UInt8], artifacts: PinArtifacts,
See PIN enrollment for the payload
reference. To wire the enrollment ceremony end to end: decode the flow nonce with `decodeNonce`, create a `PinCeremony`,
-`createPinAttestation`, submit the `add` payload with `transport_public_key` and `attestation_ios`, then `openSealedSecret` on the
-returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony` go out of scope
-so its transport key is destroyed.
+`createPinAttestation`, submit the `deviceauthn_register` payload with `transport_public_key` and `attestation_ios`, then
+`openSealedSecret` on the returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the
+`PinCeremony` go out of scope so its transport key is destroyed.
## Biometric keys