# Start authentication

Starts a WebAuthn authentication process using a secondary device. If successful, the response contains a `credential_request_options` field that should be passed to the WebAuthn `navigator.credentials.get()` API call. **Note:** Some fields, such as `challenge` and each `id` in the `allowCredentials` list, are binary values represented as base64url-encoded strings. Before calling the WebAuthn API, parse the options using `PublicKeyCredential.parseRequestOptionsFromJSON()`.

Endpoint: POST /v1/auth/webauthn/cross-device/authenticate/start

## Request fields (application/json):

  - `cross_device_ticket_id` (string, required)
    Returned upon initializing the authentication flow

## Response 200 fields (application/json):

  - `webauthn_session_id` (string, required)
    WebAuthn session identifier

  - `credential_request_options` (object, required)

  - `credential_request_options.allowCredentials` (array, required)

  - `credential_request_options.allowCredentials.type` (string, required)
    Key type. Should always be `public-key`
    Enum: "public-key"

  - `credential_request_options.allowCredentials.id` (string, required)
    The credential ID

  - `credential_request_options.allowCredentials.transports` (array, required)
    Example: ["internal"]

  - `credential_request_options.rawChallenge` (string)
    Represents the natural WebAuthn challenge. Will Only be present in approval flows

  - `credential_request_options.challenge` (string, required)

  - `credential_request_options.timeout` (number)

  - `credential_request_options.rpId` (string, required)
    Relying Party ID. Must be a valid domain pre-configured in the Admin Portal for the application

  - `credential_request_options.attestation` (string)
    Enum: "none"

  - `credential_request_options.userVerification` (string)
    Enum: "preferred", "required"

  - `credential_request_options.extensions` (object)

## Response 400 examples:

  - `InvalidRequest` (unknown)

## Response 404 examples:

  - `CrossDeviceTicketNotFound` (unknown)
    When the ticketId doesn't exist

