API

Passkeys

24 steps 21 files 1 packages 1 dependencies

This pack adds passkeys to your API as JSON endpoints, as a way to sign in without a password. It fits the guard your app authenticates with, access tokens or session, and hands you a brief for the frontend half.

  • A passkey sign-in returns the same credential as your password login, and the device picks the account, so there is no email to type.
  • A passkey sign-in completes the login on its own, since the device already checked the user's fingerprint, face, or screen lock.
  • New passkeys are named after the password manager or device that holds them, such as iCloud Keychain, and users can rename or remove them.
  • The account owner gets an email whenever a passkey is added or removed.
  • Every login response carries the signals your frontend passes to the browser to keep the user's password manager in sync.

Apply the passkeys pack with Flow. Start a new session in your selected coding agent and execute the following slash command inside it.

$ claude
> /flow.apply passkeys

After applying, Flow will make the following changes to your app.

  • Discover your default guard, access tokens or session, so a passkey sign-in finishes on the credential you already issue.

  • Ask you for your app name and your frontend's passkey domain and origins for each environment, offering defaults from your config.

  • Land the backend as shipped, from the migrations and model mixin through the transformer, validators, controllers, routes, and the change-notification mailer.

  • Add the passkey signals to your login response, and to every other action that completes a login.

  • Run the tests, drive the endpoints, and hand you a brief for the frontend to build against.

Terms & License Agreement