# Init logged-out registration

Initializes a flow that will register WebAuthn credentials using a secondary device. Requested by the access device (e.g., desktop) for a user that isn't logged in via Transmit (e.g., after password login via an external identity provider). Returns `cross_device_ticket_id`, which should be passed to the biometric device to start the device registration, such as by encoding it in a QR code. **Required permissions**: `apps:execute`, `[appId]:execute`, `auth:execute`.

Endpoint: POST /v1/auth/webauthn/cross-device/external/register/init
Security: ClientAccessToken

## Security:

  - `ClientAccessToken` (unknown)
    oauth2

## Request fields (application/json):

  - `external_user_id` (string, required)
    A unique identifier in the tenant, which corresponds to an identifier of the user in your system.

  - `username` (string, required)
    Account name for this Relying Party. This is used both for display purposes, as well as during recovery flows where the user is asked for the account name.

## Response 200 fields (application/json):

  - `cross_device_ticket_id` (string, required)
    Identifies the cross-device flow. Required for starting the flow on the secondary device.

## Response 400 examples:

  - `InvalidRequest` (unknown)

## Response 404 examples:

  - `ClientNotFound` (unknown)
    When the clientId doesn't exist

