---
title: "Exchange passkey code for tokens"
method: POST
path: "/auth/passkey/exchange"
tags: ["auth"]
---

# Exchange passkey code for tokens

`POST /auth/passkey/exchange`

Exchange one-time code for tokens (passkey redirect flow)

## Request body

- object
  - `code` string, required

## Response `200`

Default Response

- object
  - `token` string, required
  - `refreshToken` string, required

## Other responses

- `400` — Default Response
- `401` — Default Response

## Changes

> 4 revisions in range; 1 could not be searched.

- **2026-01-14** `4f6c72308c7a` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/blockmatic/apis/basilic-api/changes/auth/passkey/exchange/post.md)

---

[API](https://skmtc.dev/blockmatic/apis/basilic-api.md) · [All operations](https://skmtc.dev/blockmatic/apis/basilic-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/blockmatic/basilic-api/revisions/b2c23a2d8170/schema)
