Skip to content

Register an App Attest key​

POST
/app-attest/attest

Register a device key with its attestation. The server verifies the
certificate chain to Apple's App Attestation Root CA, that the
attestation was made for challenge
(clientDataHash = SHA256(UTF-8 bytes of challenge)), the App ID, the
environment, a zero counter and that key_id is the key's hash, then
stores the public key. Attest once per key; attesting a key that is
already registered changes nothing.

Public (guests call it). Rate limited to 10 a minute per address.

Request Body​

application/json
JSON
{
"key_id": "string",
"attestation": "string",
"challenge": "string"
}

Responses​

Key verified and registered.

Playground​

Server
Body

Samples​

Powered by VitePress OpenAPI

Built with VitePress