---
title: "Register WebAuthn credential"
method: POST
path: "/users/@me/mfa/webauthn/credentials"
tags: ["Users"]
---

# Register WebAuthn credential

`POST /users/@me/mfa/webauthn/credentials`

Complete registration of a new WebAuthn credential (security key or biometric device) using a challenge created after sudo mode verification.

## Request body

- WebAuthnRegisterRequest
  - `response` object, required — WebAuthn registration response
  - `challenge` string, required — The challenge from registration options
  - `name` string, required — User-assigned name for the credential

## Response `204`

No Content

## Other responses

- `400` — Bad Request - The request was malformed or contained invalid data
- `401` — Unauthorized - Authentication is required or the token is invalid
- `403` — Forbidden - You do not have permission to perform this action
- `429` — Too Many Requests - You are being rate limited
- `500` — Internal Server Error - An unexpected error occurred

## Changes

- **2026-09-05** `4dbb738a3e22` — 4 info
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `400`
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `401`
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `403`
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `500`
- **2026-09-03** `fa36b1b48ca5` — 20 info
  - removed the `INVALID_PACK_TYPE` enum value from the `code` response property for the response status `400`
  - removed the `INVALID_PACK_TYPE` enum value from the `code` response property for the response status `401`
  - removed the `INVALID_PACK_TYPE` enum value from the `code` response property for the response status `403`
  - removed the `INVALID_PACK_TYPE` enum value from the `code` response property for the response status `500`
  - …16 more

[Change history](https://skmtc.dev/fluxer/apis/fluxer-api/changes/users/@me/mfa/webauthn/credentials/post.md)

---

[API](https://skmtc.dev/fluxer/apis/fluxer-api.md) · [All operations](https://skmtc.dev/fluxer/apis/fluxer-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/fluxer/fluxer-api/revisions/4dbb738a3e22/schema)
