# Authenticate with mobile biometrics

Completes authentication in Transmit. Before calling this API, invoke the client-side SDK provided by Transmit to sign a challenge using the private key stored by the device, which only occurs after the user verifies themselves with biometrics. Returns an access token for the user associated with the key.

Endpoint: POST /v1/auth/mobile-biometrics/authenticate
Security: ClientAccessToken

## Security:

  - `ClientAccessToken` (unknown)
    oauth2

## Request fields (application/json):

  - `resource` (string)
    Resource URI the authentication request is attempting to access, which is reflected in the audience (`aud` claim) of the access token. This must be configured as resource for the application.

  - `claims` (object)
    Used to request additional claims in the ID token, such as roles, permissions, and other user profile data. The structure is per the [OIDC Standard](https://openid.net/specs/openid-connect-core-1_0-final.html#ClaimsParameter). For supported claims and how to request custom claims, see the [ID Token Reference](https://developer.transmitsecurity.com/openapi/id_token_reference/).
    Example: {"id_token":{"roles":null}}

  - `claims.id_token` (object)

  - `claims.access_token` (object)

  - `org_id` (string)
    Organization ID, used for member login in B2B scenarios

  - `client_attributes` (object)
    Client attributes

  - `client_attributes.user_agent` (string)

  - `client_attributes.ip_address` (string)

  - `device_id` (string)
    Identifier of the device from which the authentication request originates

  - `session_id` (string)
    Used to associate the authentication with an existing session (such as for MFA). If unspecified, a new session is created and the session ID is returned.

  - `signature` (string, required)
    Signed challenge returned by SDK authentication call

  - `challenge` (string, required)
    A string used to create attestation

  - `key_id` (string, required)
    ID of the key

  - `identifier` (string, required)
    User identifier, which may correspond to the user's email, phone number, username, or user ID. The type of identifier should be specified as the `identifier_type`.

  - `identifier_type` (string, required)
    Type of user identifier used for login

  - `user_id` (string, required)
    ID of the user

## Response 200:

  - `200` (unknown)
    Returns user tokens

## Response 200 fields (application/json):

  - `access_token` (string, required)
    User access token for accessing endpoints on behalf of the authenticated user.

  - `id_token` (string)
    ID token that identifies the user.

  - `refresh_token` (string)
    Refresh token used to refresh an expired access token.

  - `token_type` (string, required)
    Bearer.

  - `expires_in` (number, required)
    Expiration time of the access token in seconds.

  - `session_id` (string, required)
    ID of the session in which the authentication occurs.

  - `signing_artifacts` (any)
    Cryptographic data required to independently verify a transaction approval outside Mosaic. Returned when `approval_data` is provided for a supported transaction-signing flow; fields vary by authenticator.

  - `signing_artifacts.approval_data` (object, required)
    Transaction data provided when the transaction-signing flow was started. Returned after a successful approval.
    Example: {"transaction_id":"eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT","sum":"200"}

  - `signing_artifacts.public_key` (string, required)
    Public key used to verify the signature.

  - `signing_artifacts.signature` (string, required)
    Signature generated by the passkey authenticator.

  - `signing_artifacts.credential_id` (string, required)
    Identifier of the passkey credential used for the approval.

  - `signing_artifacts.webauthn_session_id` (string, required)
    Identifier of the WebAuthn authentication session.

  - `signing_artifacts.authenticator_data` (string, required)
    Base64url-encoded data returned by the passkey authenticator as part of the WebAuthn assertion.

  - `signing_artifacts.client_data_json` (string, required)
    Base64url-encoded client data from the WebAuthn authentication response.

  - `signing_artifacts.raw_challenge` (string, required)
    Raw pre-hash challenge used to bind the signature to the approval data.

  - `signing_artifacts.signature` (string, required)
    Signature generated for the transaction-signing challenge.

  - `signing_artifacts.challenge` (string, required)
    Challenge used to generate the signature and bind it to the approval data.

  - `signing_artifacts.algorithm` (object, required)
    Parameters required to verify the signature.

  - `signing_artifacts.algorithm.name` (string, required)
    Signature algorithm used to verify the signature, for example `ecdsa` or `rsa-pss`.

  - `signing_artifacts.algorithm.hash` (string)
    Hash algorithm used to verify the signature, for example `sha-256`.

  - `signing_artifacts.algorithm.saltLength` (number)
    Length, in bytes, of the salt used by RSA-PSS.

  - `signing_artifacts.algorithm.namedCurve` (string)
    Elliptic curve used by ECDSA, for example `P-256`.

## Response 400:

  - `400` (unknown)
    Invalid signature, user not found, or session not found

## Response 400 fields (application/json):

  - `error_code` (string)
    Enum: "auth_invalid_signature", "user_not_found", "session_not_found"

  - `message` (string)

