Embedded Wallet Auth

Re-issue an authentication credential challenge

Re-issue the challenge for an existing authentication credential.

For EMAIL_OTP credentials, this triggers a new one-time password email to the address on file. The response is a plain AuthMethod; there is no challenge body to surface because the OTP is delivered out-of-band via email. After the user receives the new OTP, call POST /auth/credentials/{id}/verify to complete verification and issue a session.

For PASSKEY credentials, this issues a fresh Grid-generated WebAuthn challenge for reauthentication. The response is a PasskeyAuthChallenge — the base AuthMethod fields plus the new challenge, requestId, and expiresAt. The client passes the challenge into navigator.credentials.get() and submits the resulting assertion to POST /auth/credentials/{id}/verify with Request-Id: <requestId> to receive a session.

post/auth/credentials/{id}/challenge

Path parameters

idstring required

The id of the authentication credential to re-challenge (the id field of the AuthMethod returned from POST /auth/credentials).

Response

Challenge re-issued for the authentication credential. For EMAIL_OTP the body is a plain AuthMethod and a new OTP email has been sent. For PASSKEY the body is a PasskeyAuthChallenge carrying the freshly issued challenge, requestId, and expiresAt required to complete reauthentication via POST /auth/credentials/{id}/verify.

OR

Example response

{
  "id": "AuthMethod:019542f5-b3e7-1d02-0000-000000000001",
  "accountId": "InternalAccount:019542f5-b3e7-1d02-0000-000000000002",
  "nickname": "example@lightspark.com",
  "createdAt": "2026-04-08T15:30:01Z",
  "updatedAt": "2026-04-08T15:35:00Z"
}

Changes