# Init authentication

Initializes a flow that will authenticate WebAuthn credentials using a secondary device. Requested by the access device (e.g., desktop) before delegating authentication to another device. Returns a cross-device ticket ID that should be passed to the biometric device to start the authentication (e.g., by encoding it in a QR code).

Endpoint: POST /v1/auth/webauthn/cross-device/authenticate/init

## Request fields (application/json):

  - `client_id` (string, required)
    The client ID of the application the user is trying to authenticate to.

  - `username` (string)
    Name of user account, as used in the WebAuthn registration. If not provided, the authentication will start without the context of a user and it will be inferred by the chosen passkey

  - `approval_data` (object)
    Flat object that contains the data that your customer should approve for a transaction signing or custom approval flow. It can contain up to 10 keys, and only alphanumeric characters, underscores, hyphens, and periods. It will be returned as a claim in the ID token upon successful authentication.
    Example: {"transaction_id":"eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT","sum":"200"}

## Response 200 fields (application/json):

  - `cross_device_ticket_id` (string, required)
    Identifies the cross-device flow. Required for starting the flow on the secondary device.

## Response 400 examples:

  - `InvalidRequest` (unknown)

## Response 404 examples:

  - `ClientNotFound` (unknown)
    When the clientId doesn't exist

