# Register for logged-in user

Complete WebAuthn credential registration for a user that is currently logged in using a different Transmit authentication method. This API must be called from the backend using the user access token returned upon successful authentication. If successful, the credential will be registered for the user that corresponds to the authorization token.

Endpoint: POST /v1/auth/webauthn/register
Security: UserAccessToken

## Security:

  - `UserAccessToken` (unknown)
    http bearer JWT

## Request fields (application/json):

  - `webauthn_encoded_result` (string, required)
    WebAuthn attestation data returned by the browser upon credential creation. If the credential was created using `navigator.credentials.create()`, call `toJSON()` on the returned `PublicKeyCredential` before sending it to the backend. Optionally include `deviceInfo` (`publicKeyId`, `publicKey`) in the same object to bind the device to the user, so it appears in the `device_keys` claim of the ID token after passkey login.

  - `device_id` (string)
    The device associated with this registration.

## Response 200:

  - `200` (unknown)
    Registered credential details

## Response 200 fields (application/json):

  - `webauthn_session_id` (string, required)
    WebAuthn session identifier

  - `user_id` (string)
    Transmit user ID, autogenerated upon user creation

  - `webauthn_username` (string, required)
    Name of user account, as specified in the WebAuthn registration

  - `credential_id` (string, required)
    WebAuthn credential ID

  - `authenticator_attachment` (string, required)
    The authenticators' attachment modalities. Cross-platform authenticator are external to the current device, such as a USB security key or a different device
    Enum: "platform", "cross-platform"

  - `aaguid` (string)
    The authenticator's AAGUID

## Response 400:

  - `400` (unknown)
    Invalid encoded result, client ID mismatch, or credential name already exists

## Response 400 fields (application/json):

  - `error_code` (string)
    Enum: "auth_webauthn_invalid_encoded_result", "client_id_mismatch", "auth_webauthn_credential_name_already_exists"

  - `message` (string)

## Response 401:

  - `401` (unknown)
    Invalid origin or credentials

## Response 401 fields (application/json):

  - `error_code` (string)
    Enum: "auth_webauthn_invalid_session", "auth_webauthn_invalid_origin_error", "auth_webauthn_origin_not_allowed", "auth_invalid_credentials"

  - `message` (string)

## Response 404 examples:

  - `ClientNotFound` (unknown)

