Delete a passkey
const url = 'https://api.aetherpush.com/v1/mfa/passkeys/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0';const options = { method: 'DELETE', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"stepUp":{"type":"passkey","response":{},"code":"example"}}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request DELETE \ --url https://api.aetherpush.com/v1/mfa/passkeys/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0 \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "stepUp": { "type": "passkey", "response": {}, "code": "example" } }'Deleting the account’s last passkey disables MFA only when no confirmed authenticator app remains either; in that case the remaining recovery codes are discarded and pending MFA logins are invalidated. When MFA is enabled, a fresh step-up proof of an existing factor is required.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Request Body
Section titled “Request Body”object
Fresh proof of a second factor the account already holds, required to change the factor set once MFA is enabled. A stolen session cannot enrol its own factor and then strip the owner’s. Recovery codes and passwords are deliberately not accepted here: a recovery code recovers a login but never authorizes a factor change.
object
WebAuthn AuthenticationResponseJSON. Required when type is passkey.
object
A current authenticator code. Required when type is totp.
Responses
Section titled “Responses”Passkey deleted.
object
False when the account is left with no MFA method at all (no passkeys and no confirmed authenticator app); MFA is then disabled and the remaining recovery codes are discarded.
Examplegenerated
{ "message": "example", "mfaEnabled": true}Authentication required, or step-up is required and not satisfied (code: step_up_required).
object
Human-readable error message.
Unique identifier for the request, also exposed as the X-Request-Id response header.
Returned when a factor-set change on an MFA-enabled account arrives
without a fresh step-up proof. Same shape as the reauth response so
clients branch on code and open the step-up flow, not on message text.
object
Example
{ "error": "The requested resource was not found.", "requestId": "req_abc123"}API keys and named access keys cannot manage passkeys; a login session is required.
object
Human-readable error message.
Unique identifier for the request, also exposed as the X-Request-Id response header.
Example
{ "error": "The requested resource was not found.", "requestId": "req_abc123"}Passkey not found.
object
Human-readable error message.
Unique identifier for the request, also exposed as the X-Request-Id response header.
Example
{ "error": "The requested resource was not found.", "requestId": "req_abc123"}