Skip to main content
DELETE
Delete

Authorizations

Authorization
string
header
required

Only available to a signed-in whop.com session. API keys, access tokens, and OAuth tokens are not accepted.

Headers

Api-Version-Date
string

Pins the request to a dated API version.

Example:

"2026-09-29"

Path Parameters

id
string
required

Passkey ID, prefixed wcred_.

Body

application/json
authenticator_data
string
required

The authenticatorData from the WebAuthn assertion, base64url-encoded.

Example:

"YXV0aGVudGljYXRvci1kYXRh"

client_data_json
string
required

The clientDataJSON from the WebAuthn assertion, base64url-encoded.

Example:

"Y2xpZW50LWRhdGE"

signature
string
required

The signature from the WebAuthn assertion, base64url-encoded.

Example:

"c2lnbmF0dXJl"

Response

passkey deleted

deleted
boolean
required

Always true: the passkey was removed.

Example:

true

id
string
required

The ID of the deleted passkey.

Example:

"wcred_xxxxxxxxxxxxxx"