# Start registration

Starts a WebAuthn registration process on a secondary device, and returns a challenge for the client to sign. If successful, the response contains a `credential_creation_options` field that should be passed to the WebAuthn `navigator.credentials.create()` API call. **Note:** Some fields, such as `user.id` and `challenge`, are binary values represented as base64url-encoded strings. Before calling the WebAuthn API, parse the options using `PublicKeyCredential.parseCreationOptionsFromJSON()`.

Endpoint: POST /v1/auth/webauthn/cross-device/register/start

## Request fields (application/json):

  - `cross_device_ticket_id` (string, required)
    cross device ticket id returned from the init cross device registration API

## Response 200 fields (application/json):

  - `webauthn_session_id` (string, required)
    WebAuthn session identifier

  - `credential_creation_options` (object, required)

  - `credential_creation_options.attestation` (string)
    Enum: "none"

  - `credential_creation_options.authenticatorSelection` (object)

  - `credential_creation_options.authenticatorSelection.authenticatorAttachment` (string)
    The authenticators' attachment modalities. Cross-platform authenticator are external to the current device, such as a USB security key or a different device
    Enum: "platform", "cross-platform"

  - `credential_creation_options.authenticatorSelection.requireResidentKey` (boolean)

  - `credential_creation_options.authenticatorSelection.residentKey` (object)

  - `credential_creation_options.authenticatorSelection.userVerification` (string)
    Enum: "preferred", "required"

  - `credential_creation_options.extensions` (object)

  - `credential_creation_options.extensions.appid` (string)

  - `credential_creation_options.extensions.credProps` (boolean)

  - `credential_creation_options.extensions.hmacCreateSecret` (boolean)

  - `credential_creation_options.excludeCredentials` (array)

  - `credential_creation_options.pubKeyCredParams` (array, required)

  - `credential_creation_options.pubKeyCredParams.alg` (number, required)

  - `credential_creation_options.pubKeyCredParams.type` (string, required)
    Key type. Should always be `public-key`
    Enum: "public-key"

  - `credential_creation_options.timeout` (number)

  - `credential_creation_options.challenge` (string, required)

  - `credential_creation_options.user` (object, required)

  - `credential_creation_options.user.id` (string, required)
    User handle

  - `credential_creation_options.user.name` (string, required)
    The webauthn username

  - `credential_creation_options.user.displayName` (string, required)
    The user display name

  - `credential_creation_options.rp` (object, required)

  - `credential_creation_options.rp.id` (string, required)
    Relying Party ID. Must be a valid domain pre-configured in the Admin Portal for the application

  - `credential_creation_options.rp.name` (string, required)
    Relying party displayable name

  - `credential_creation_options.rp.icon` (string, required)

## Response 400 examples:

  - `InvalidRequest` (unknown)

## Response 404 examples:

  - `CrossDeviceTicketNotFound` (unknown)
    When the ticketId doesn't exist

