---
title: "List WebAuthn credentials"
method: GET
path: "/users/@me/mfa/webauthn/credentials"
tags: ["Users"]
---

# List WebAuthn credentials

`GET /users/@me/mfa/webauthn/credentials`

Retrieve all registered WebAuthn credentials (security keys, biometric devices) for the current user. Requires authentication.

## Response `200`

Success

- WebAuthnCredentialResponse[]
  - `id` string, required — The credential ID
  - `name` string, required — User-assigned name for the credential
  - `created_at` string, required — When the credential was registered
  - `last_used_at` string, nullable, required — When the credential was last used

## Other responses

- `400` — Bad Request - The request was malformed or contained invalid data
- `401` — Unauthorized - Authentication is required or the token is invalid
- `403` — Forbidden - You do not have permission to perform this action
- `429` — Too Many Requests - You are being rate limited
- `500` — Internal Server Error - An unexpected error occurred

---

[API](https://skmtc.dev/fluxer/apis/fluxer-api.md) · [All operations](https://skmtc.dev/fluxer/apis/fluxer-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/fluxer/fluxer-api/revisions/d9c706133cc5/schema)
