Skip to main content
POST
Create Challenge

Authorizations

Authorization
string
header
required

Only available to a signed-in whop.com session. API keys, access tokens, and OAuth tokens are not accepted.

Headers

Idempotency-Key
string

A unique key that makes this request safe to retry. See Idempotent requests.

Maximum string length: 255
Example:

"d9105228-4a08-46b1-8b91-42fed586d383"

Api-Version-Date
string

Pins the request to a dated API version.

Example:

"2026-09-29"

Body

application/json
challenge_type
enum<string>
required

The ceremony this challenge is for.

Available options:
registration,
deletion
Example:

"registration"

passkey_id
string

The passkey the ceremony targets, prefixed wcred_. Required when challenge_type is deletion, ignored otherwise.

Example:

"wcred_xxxxxxxxxxxxxx"

Response

challenge minted

challenge
string
required

The challenge to pass to the WebAuthn ceremony, base64url-encoded without padding.

Example:

"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"