Skip to content

Validate device key

Request

Verifies that the user's device is in their possession. Before calling this API, the device signs a challenge using the private key stored by the device. This API is used to verify the signed challenge using the device public key. In case the device is blocked, this validation will fail.

Note: The challenge should be generated by your client backend..

Required permissions: apps:execute, [appId]:execute, devices:execute.

Security
ClientAccessToken
Path
user_idstringrequired

ID of the user

key_idstringrequired

An identifier for the user's device

Bodyapplication/jsonrequired
challengestringrequired

Raw challenge before it was signed by the device

signaturestringrequired

Signed challenge

curl -i -X POST \
  'https://api.sbx.transmitsecurity.io/cis/v1/users/{user_id}/device-keys/{key_id}/validate' \
  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "challenge": "string",
    "signature": "string"
  }'

Responses

Bodyapplication/json
resultbooleanread-onlyrequired

Boolean value indicating if device key validation succeeded

Response
{ "result": true }