WebAuthn 2nd-factor: assertion options bound to the pending challenge

Authenticate every request with Authorization: Bearer <token> — a JWT or API token.

Download OpenAPI JSON