curl --request DELETE \
--url https://api.whop.com/api/v1/users/me/passkeys/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"authenticator_data": "YXV0aGVudGljYXRvci1kYXRh",
"client_data_json": "Y2xpZW50LWRhdGE",
"signature": "c2lnbmF0dXJl"
}
'import requests
url = "https://api.whop.com/api/v1/users/me/passkeys/{id}"
payload = {
"authenticator_data": "YXV0aGVudGljYXRvci1kYXRh",
"client_data_json": "Y2xpZW50LWRhdGE",
"signature": "c2lnbmF0dXJl"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.delete(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'DELETE',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
authenticator_data: 'YXV0aGVudGljYXRvci1kYXRh',
client_data_json: 'Y2xpZW50LWRhdGE',
signature: 'c2lnbmF0dXJl'
})
};
fetch('https://api.whop.com/api/v1/users/me/passkeys/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.whop.com/api/v1/users/me/passkeys/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_POSTFIELDS => json_encode([
'authenticator_data' => 'YXV0aGVudGljYXRvci1kYXRh',
'client_data_json' => 'Y2xpZW50LWRhdGE',
'signature' => 'c2lnbmF0dXJl'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.whop.com/api/v1/users/me/passkeys/{id}"
payload := strings.NewReader("{\n \"authenticator_data\": \"YXV0aGVudGljYXRvci1kYXRh\",\n \"client_data_json\": \"Y2xpZW50LWRhdGE\",\n \"signature\": \"c2lnbmF0dXJl\"\n}")
req, _ := http.NewRequest("DELETE", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.delete("https://api.whop.com/api/v1/users/me/passkeys/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"authenticator_data\": \"YXV0aGVudGljYXRvci1kYXRh\",\n \"client_data_json\": \"Y2xpZW50LWRhdGE\",\n \"signature\": \"c2lnbmF0dXJl\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.whop.com/api/v1/users/me/passkeys/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Delete.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"authenticator_data\": \"YXV0aGVudGljYXRvci1kYXRh\",\n \"client_data_json\": \"Y2xpZW50LWRhdGE\",\n \"signature\": \"c2lnbmF0dXJl\"\n}"
response = http.request(request)
puts response.read_body{
"deleted": true,
"id": "wcred_xxxxxxxxxxxxxx"
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}Delete
Deletes one of the authenticated user’s own passkeys. The request body carries a WebAuthn assertion from the passkey being deleted, so possession of the credential is proven before it is removed: mint a deletion challenge for it first, run the ceremony with that passkey, and send the result here. Deleting the user’s last passkey is allowed — their other step-up factors remain. Requires a user session.
curl --request DELETE \
--url https://api.whop.com/api/v1/users/me/passkeys/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"authenticator_data": "YXV0aGVudGljYXRvci1kYXRh",
"client_data_json": "Y2xpZW50LWRhdGE",
"signature": "c2lnbmF0dXJl"
}
'import requests
url = "https://api.whop.com/api/v1/users/me/passkeys/{id}"
payload = {
"authenticator_data": "YXV0aGVudGljYXRvci1kYXRh",
"client_data_json": "Y2xpZW50LWRhdGE",
"signature": "c2lnbmF0dXJl"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.delete(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'DELETE',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
authenticator_data: 'YXV0aGVudGljYXRvci1kYXRh',
client_data_json: 'Y2xpZW50LWRhdGE',
signature: 'c2lnbmF0dXJl'
})
};
fetch('https://api.whop.com/api/v1/users/me/passkeys/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.whop.com/api/v1/users/me/passkeys/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_POSTFIELDS => json_encode([
'authenticator_data' => 'YXV0aGVudGljYXRvci1kYXRh',
'client_data_json' => 'Y2xpZW50LWRhdGE',
'signature' => 'c2lnbmF0dXJl'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.whop.com/api/v1/users/me/passkeys/{id}"
payload := strings.NewReader("{\n \"authenticator_data\": \"YXV0aGVudGljYXRvci1kYXRh\",\n \"client_data_json\": \"Y2xpZW50LWRhdGE\",\n \"signature\": \"c2lnbmF0dXJl\"\n}")
req, _ := http.NewRequest("DELETE", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.delete("https://api.whop.com/api/v1/users/me/passkeys/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"authenticator_data\": \"YXV0aGVudGljYXRvci1kYXRh\",\n \"client_data_json\": \"Y2xpZW50LWRhdGE\",\n \"signature\": \"c2lnbmF0dXJl\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.whop.com/api/v1/users/me/passkeys/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Delete.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"authenticator_data\": \"YXV0aGVudGljYXRvci1kYXRh\",\n \"client_data_json\": \"Y2xpZW50LWRhdGE\",\n \"signature\": \"c2lnbmF0dXJl\"\n}"
response = http.request(request)
puts response.read_body{
"deleted": true,
"id": "wcred_xxxxxxxxxxxxxx"
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}{
"error": {
"message": "account_id is required",
"type": "bad_request",
"code": "<string>"
}
}Authorizations
Only available to a signed-in whop.com session. API keys, access tokens, and OAuth tokens are not accepted.
Headers
Pins the request to a dated API version.
"2026-09-29"
Path Parameters
Passkey ID, prefixed wcred_.
Body
The authenticatorData from the WebAuthn assertion, base64url-encoded.
"YXV0aGVudGljYXRvci1kYXRh"
The clientDataJSON from the WebAuthn assertion, base64url-encoded.
"Y2xpZW50LWRhdGE"
The signature from the WebAuthn assertion, base64url-encoded.
"c2lnbmF0dXJl"

