Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 12 additions & 13 deletions src/components/Shared/kratos/passwordless/deviceauthn/android.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -57,9 +57,7 @@ all options; an empty list disables the check.

```json
{
"delete": {
"client_key_id": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c"
},
"deviceauthn_remove": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c",
"method": "deviceauthn"
}
```
Expand All @@ -74,8 +72,7 @@ all options; an empty list disables the check.
val body = UpdateSettingsFlowBody()
val method = UpdateSettingsFlowWithDeviceAuthnMethod()
method.method = "deviceauthn"
method.delete = UpdateSettingsFlowWithDeviceAuthnMethodDelete()
method.delete!!.clientKeyId = clientKeyIdToDelete
method.deviceauthnRemove = clientKeyIdToDelete
body.actualInstance = method
val updatedFlow = apiInstance.updateSettingsFlow(settingsFlow?.id, body, sessionToken, "")
```
Expand All @@ -90,8 +87,9 @@ all options; an empty list disables the check.
```json
{
"method": "deviceauthn",
"add": {
"deviceauthn_register": {
"device_name": "Pixel 9",
"version": 1,
"certificate_chain_android": ["...", "...", "..."]
}
}
Expand All @@ -113,9 +111,10 @@ all options; an empty list disables the check.
val body = UpdateSettingsFlowBody()
val method = UpdateSettingsFlowWithDeviceAuthnMethod()
method.method = "deviceauthn"
method.add = UpdateSettingsFlowWithDeviceAuthnMethodAdd()
method.add!!.deviceName = "My work phone"
method.add!!.certificateChainAndroid = keyCertChain.map { it.encoded }.toList()
method.deviceauthnRegister = UpdateSettingsFlowWithDeviceAuthnMethodRegister()
method.deviceauthnRegister!!.deviceName = "My work phone"
method.deviceauthnRegister!!.version = 1
method.deviceauthnRegister!!.certificateChainAndroid = keyCertChain.map { it.encoded }.toList()
body.actualInstance = method
val updatedFlow = apiInstance.updateSettingsFlow(settingsFlow?.id, body, sessionToken, "")

Expand Down Expand Up @@ -701,10 +700,10 @@ discipline when you wire these calls.

1. **Enroll** (<SameDeploymentLink to="kratos/passwordless/deviceauthn#pin-enrollment">PIN enrollment</SameDeploymentLink>) —
`decodeNonce` the flow's `deviceauthn_nonce` node, `createSealingKey`, create a `PinCeremony`, then
`createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `add` payload with `transport_public_key` and the
returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the `continue_with` item, derive the
fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony`
go out of scope so its transport key is destroyed.
`createPinSigningKey(alias, nonce, transportPublicKey)` and submit the `deviceauthn_register` payload with
`transport_public_key` and the returned chain as `certificate_chain_android`. On the response, `openSealedSecret` on the
`continue_with` item, derive the fingerprint with `clientKeyId(alias)`, capture the PIN, `PinVault.seal`, and persist the
`PinArtifacts`. Let the `PinCeremony` go out of scope so its transport key is destroyed.
2. **Log in** (<SameDeploymentLink to="kratos/passwordless/deviceauthn#first-factor-login">First-factor
login</SameDeploymentLink>) — `decodeNonce`, `PinVault.unseal` with the entered PIN, `pinProof(pinSecret, clientKeyId, nonce)`,
and `sign(alias, nonce)` over the raw nonce, then submit `client_key_id`, `signature`, and `pin_proof`.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -275,7 +275,7 @@ Runs in a settings flow under a privileged session.
```json
{
"method": "deviceauthn",
"add": {
"deviceauthn_register": {
"device_name": "My work phone",
"version": 1,
"pin_protected": true,
Expand Down
20 changes: 9 additions & 11 deletions src/components/Shared/kratos/passwordless/deviceauthn/ios.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -67,9 +67,7 @@ all options; an empty list disables the check.

```json
{
"delete": {
"client_key_id": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c"
},
"deviceauthn_remove": "9c62918cbbef2e94c3a10238bd57ab196e3a2caae1a44f28b02f2d1a72b1e59c",
"method": "deviceauthn"
}
```
Expand All @@ -86,9 +84,7 @@ all options; an empty list disables the check.
let body: UpdateSettingsFlowBody =
.typeUpdateSettingsFlowWithDeviceAuthnMethod(
UpdateSettingsFlowWithDeviceAuthnMethod(
delete: UpdateSettingsFlowWithDeviceAuthnMethodDelete(
clientKeyId: clientKeyId,
),
deviceauthnRemove: clientKeyId,
method: "deviceauthn"
)
)
Expand All @@ -109,8 +105,9 @@ all options; an empty list disables the check.
```json
{
"method": "deviceauthn",
"add": {
"deviceauthn_register": {
"device_name": "iPhone (iPhone14,5)",
"version": 1,
"attestation_ios": "..."
}
}
Expand All @@ -132,9 +129,10 @@ all options; an empty list disables the check.
let body: UpdateSettingsFlowBody =
.typeUpdateSettingsFlowWithDeviceAuthnMethod(
UpdateSettingsFlowWithDeviceAuthnMethod(
add: UpdateSettingsFlowWithDeviceAuthnMethodAdd(
deviceauthnRegister: UpdateSettingsFlowWithDeviceAuthnMethodRegister(
attestationIos: attestation,
deviceName: deviceName,
version: 1,
),
method: "deviceauthn"
)
Expand Down Expand Up @@ -585,9 +583,9 @@ func loginWithPin(flowNonce: Data, pin: inout [UInt8], artifacts: PinArtifacts,

See <SameDeploymentLink to="kratos/passwordless/deviceauthn#pin-enrollment">PIN enrollment</SameDeploymentLink> for the payload
reference. To wire the enrollment ceremony end to end: decode the flow nonce with `decodeNonce`, create a `PinCeremony`,
`createPinAttestation`, submit the `add` payload with `transport_public_key` and `attestation_ios`, then `openSealedSecret` on the
returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the `PinCeremony` go out of scope
so its transport key is destroyed.
`createPinAttestation`, submit the `deviceauthn_register` payload with `transport_public_key` and `attestation_ios`, then
`openSealedSecret` on the returned `continue_with`, capture the PIN, `PinVault.seal`, and persist the `PinArtifacts`. Let the
`PinCeremony` go out of scope so its transport key is destroyed.

## Biometric keys

Expand Down
Loading