From 7831168379c547017aff1e3904bf1e93a4f49c36 Mon Sep 17 00:00:00 2001 From: Pierre Caillaud Date: Fri, 24 Jul 2026 09:19:10 +0200 Subject: [PATCH 1/2] docs: update renamed deviceauthn fields references --- .../passwordless/deviceauthn/android.mdx | 19 +++++++++---------- .../kratos/passwordless/deviceauthn/index.mdx | 2 +- .../kratos/passwordless/deviceauthn/ios.mdx | 16 +++++++--------- 3 files changed, 17 insertions(+), 20 deletions(-) diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx index e2a857e30..5b203a877 100644 --- a/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx +++ b/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx @@ -57,9 +57,7 @@ all options; an empty list disables the check. ```json { - "delete": { - "client_key_id": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c" - }, + "deviceauthn_remove": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c", "method": "deviceauthn" } ``` @@ -74,8 +72,7 @@ all options; an empty list disables the check. val body = UpdateSettingsFlowBody() val method = UpdateSettingsFlowWithDeviceAuthnMethod() method.method = "deviceauthn" - method.delete = UpdateSettingsFlowWithDeviceAuthnMethodDelete() - method.delete!!.clientKeyId = clientKeyIdToDelete + method.deviceauthnRemove = clientKeyIdToDelete body.actualInstance = method val updatedFlow = apiInstance.updateSettingsFlow(settingsFlow?.id, body, sessionToken, "") ``` @@ -90,8 +87,9 @@ all options; an empty list disables the check. ```json { "method": "deviceauthn", - "add": { + "deviceauthn_register": { "device_name": "Pixel 9", + "version": 1, "certificate_chain_android": ["...", "...", "..."] } } @@ -113,9 +111,10 @@ all options; an empty list disables the check. val body = UpdateSettingsFlowBody() val method = UpdateSettingsFlowWithDeviceAuthnMethod() method.method = "deviceauthn" - method.add = UpdateSettingsFlowWithDeviceAuthnMethodAdd() - method.add!!.deviceName = "My work phone" - method.add!!.certificateChainAndroid = keyCertChain.map { it.encoded }.toList() + method.deviceauthnRegister = UpdateSettingsFlowWithDeviceAuthnMethodRegister() + method.deviceauthnRegister!!.deviceName = "My work phone" + method.deviceauthnRegister!!.version = 1 + method.deviceauthnRegister!!.certificateChainAndroid = keyCertChain.map { it.encoded }.toList() body.actualInstance = method val updatedFlow = apiInstance.updateSettingsFlow(settingsFlow?.id, body, sessionToken, "") @@ -701,7 +700,7 @@ discipline when you wire these calls. 1. **Enroll** (PIN enrollment) — `decodeNonce` the flow's `deviceauthn_nonce` node, `createSealingKey`, create a `PinCeremony`, then - `createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `add` payload with `transport_public_key` and the + `createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `deviceauthn_register` payload with `transport_public_key` and the returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the `continue_with` item, derive the fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony` go out of scope so its transport key is destroyed. diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx index 7e2b4e324..8b73b8525 100644 --- a/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx +++ b/src/components/Shared/kratos/passwordless/deviceauthn/index.mdx @@ -275,7 +275,7 @@ Runs in a settings flow under a privileged session. ```json { "method": "deviceauthn", - "add": { + "deviceauthn_register": { "device_name": "My work phone", "version": 1, "pin_protected": true, diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx index e78e2e95b..8fd2de124 100644 --- a/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx +++ b/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx @@ -67,9 +67,7 @@ all options; an empty list disables the check. ```json { - "delete": { - "client_key_id": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c" - }, + "deviceauthn_remove": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c", "method": "deviceauthn" } ``` @@ -86,9 +84,7 @@ all options; an empty list disables the check. let body: UpdateSettingsFlowBody = .typeUpdateSettingsFlowWithDeviceAuthnMethod( UpdateSettingsFlowWithDeviceAuthnMethod( - delete: UpdateSettingsFlowWithDeviceAuthnMethodDelete( - clientKeyId: clientKeyId, - ), + deviceauthnRemove: clientKeyId, method: "deviceauthn" ) ) @@ -109,8 +105,9 @@ all options; an empty list disables the check. ```json { "method": "deviceauthn", - "add": { + "deviceauthn_register": { "device_name": "iPhone (iPhone14,5)", + "version": 1, "attestation_ios": "..." } } @@ -132,9 +129,10 @@ all options; an empty list disables the check. let body: UpdateSettingsFlowBody = .typeUpdateSettingsFlowWithDeviceAuthnMethod( UpdateSettingsFlowWithDeviceAuthnMethod( - add: UpdateSettingsFlowWithDeviceAuthnMethodAdd( + deviceauthnRegister: UpdateSettingsFlowWithDeviceAuthnMethodRegister( attestationIos: attestation, deviceName: deviceName, + version: 1, ), method: "deviceauthn" ) @@ -585,7 +583,7 @@ func loginWithPin(flowNonce: Data, pin: inout [UInt8], artifacts: PinArtifacts, See PIN enrollment for the payload reference. To wire the enrollment ceremony end to end: decode the flow nonce with `decodeNonce`, create a `PinCeremony`, -`createPinAttestation`, submit the `add` payload with `transport_public_key` and `attestation_ios`, then `openSealedSecret` on the +`createPinAttestation`, submit the `deviceauthn_register` payload with `transport_public_key` and `attestation_ios`, then `openSealedSecret` on the returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony` go out of scope so its transport key is destroyed. From c43adb8da884a3c4b07548221539cf0da0d25de4 Mon Sep 17 00:00:00 2001 From: Pierre Caillaud Date: Fri, 24 Jul 2026 10:02:56 +0200 Subject: [PATCH 2/2] chore: format --- .../Shared/kratos/passwordless/deviceauthn/android.mdx | 8 ++++---- .../Shared/kratos/passwordless/deviceauthn/ios.mdx | 6 +++--- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx index 5b203a877..2d0341163 100644 --- a/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx +++ b/src/components/Shared/kratos/passwordless/deviceauthn/android.mdx @@ -700,10 +700,10 @@ discipline when you wire these calls. 1. **Enroll** (PIN enrollment) — `decodeNonce` the flow's `deviceauthn_nonce` node, `createSealingKey`, create a `PinCeremony`, then - `createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `deviceauthn_register` payload with `transport_public_key` and the - returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the `continue_with` item, derive the - fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony` - go out of scope so its transport key is destroyed. + `createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `deviceauthn_register` payload with + `transport_public_key` and the returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the + `continue_with` item, derive the fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the + `PinArtifacts`. Let the `PinCeremony` go out of scope so its transport key is destroyed. 2. **Log in** (First-factor login) — `decodeNonce`, `PinVault.unseal` with the entered PIN, `pinProof(pinSecret, clientKeyId, nonce)`, and `sign(alias, nonce)` over the raw nonce, then submit `client_key_id`, `signature`, and `pin_proof`. diff --git a/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx b/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx index 8fd2de124..00c9bcaac 100644 --- a/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx +++ b/src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx @@ -583,9 +583,9 @@ func loginWithPin(flowNonce: Data, pin: inout [UInt8], artifacts: PinArtifacts, See PIN enrollment for the payload reference. To wire the enrollment ceremony end to end: decode the flow nonce with `decodeNonce`, create a `PinCeremony`, -`createPinAttestation`, submit the `deviceauthn_register` payload with `transport_public_key` and `attestation_ios`, then `openSealedSecret` on the -returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony` go out of scope -so its transport key is destroyed. +`createPinAttestation`, submit the `deviceauthn_register` payload with `transport_public_key` and `attestation_ios`, then +`openSealedSecret` on the returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the +`PinCeremony` go out of scope so its transport key is destroyed. ## Biometric keys