# Attach device

Indicates that the auth device has engaged in the flow, such as when the user scans a QR encoding the cross-device ticket ID. This updates the flow status to `scanned`.

Endpoint: POST /v1/auth/webauthn/cross-device/attach-device

## Request fields (application/json):

  - `cross_device_ticket_id` (string, required)
    Webauthn cross device ticket ID

## Response 200 fields (application/json):

  - `status` (string, required)
    Enum: "pending", "scanned", "success", "error", "timeout", "aborted"

  - `started_at` (string)

  - `approval_data` (object)
    Flat object that contains the data that your customer should approve for a transaction signing or custom approval flow. It can contain up to 10 keys, and only alphanumeric characters, underscores, hyphens, and periods. It will be returned as a claim in the ID token upon successful authentication.
    Example: {"transaction_id":"eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT","sum":"200"}

## Response 400 examples:

  - `InvalidRequest` (unknown)

## Response 404 examples:

  - `CrossDeviceTicketNotFound` (unknown)
    When the ticketId doesn't exist

