> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trylath.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Every Lath operation is POST https://platform.trylath.com/<operation name with dots replaced by slashes>, with a JSON body and `Authorization: Bearer <key>`. `email.send` is POST /email/send.
> Branch on `error.code`, never on `error.message`. Every refusal also carries `error.fix`, which names the next step.
> Send an `Idempotency-Key` header on any operation that is not retry-safe, so a retry cannot run it twice.
> A `lath_test_` key emails only the account's own members and sends no SMS; a `lath_live_` key reaches real recipients and is billed.
> The OpenAPI document, generated from the same registry as the routes, is at https://platform.trylath.com/openapi.json.

# auth.passkey.signin.verify

> Completes a passkey sign-in with the authenticator's response from navigator.credentials.get and issues a session. User verification is required, so a passkey sign-in counts as two factors and never asks for a code afterwards.



## OpenAPI

````yaml /api-reference/openapi.json post /auth/passkey/signin/verify
openapi: 3.1.0
info:
  title: Lath API
  version: 0.1.0
  description: >-
    Every operation is one POST. The same set is reachable over MCP, the SDK and
    the CLI; nothing is dashboard-only.
servers:
  - url: https://platform.trylath.com
    description: This deployment
security: []
paths:
  /auth/passkey/signin/verify:
    post:
      tags:
        - auth
      summary: auth.passkey.signin.verify
      description: >-
        Completes a passkey sign-in with the authenticator's response from
        navigator.credentials.get and issues a session. User verification is
        required, so a passkey sign-in counts as two factors and never asks for
        a code afterwards.
      operationId: auth.passkey.signin.verify
      parameters:
        - name: Idempotency-Key
          in: header
          required: false
          schema:
            type: string
          description: >-
            Replays the stored response for the same key and input; refuses
            different input.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                challengeId:
                  type: string
                  format: uuid
                  pattern: >-
                    ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                response:
                  type: object
                  properties:
                    id:
                      type: string
                      minLength: 1
                      maxLength: 2048
                    rawId:
                      type: string
                      minLength: 1
                      maxLength: 2048
                    type:
                      type: string
                      const: public-key
                    response:
                      type: object
                      properties:
                        clientDataJSON:
                          type: string
                          minLength: 1
                          maxLength: 8192
                        authenticatorData:
                          type: string
                          minLength: 1
                          maxLength: 65536
                        signature:
                          type: string
                          minLength: 1
                          maxLength: 4096
                        userHandle:
                          anyOf:
                            - type: string
                              maxLength: 2048
                            - type: 'null'
                      required:
                        - clientDataJSON
                        - authenticatorData
                        - signature
                      additionalProperties: false
                    authenticatorAttachment:
                      type: string
                      enum:
                        - platform
                        - cross-platform
                    clientExtensionResults:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  required:
                    - id
                    - rawId
                    - type
                    - response
                  additionalProperties: false
                  description: >-
                    The PublicKeyCredential from the browser, serialised as JSON
                    (startAuthentication from @simplewebauthn/browser)
                userAgent:
                  type: string
                  maxLength: 400
              required:
                - challengeId
                - response
              additionalProperties: false
      responses:
        '200':
          description: '{ activityId, result }. activityId is empty for reads.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  activityId:
                    type: string
                    description: The activity this call created, or empty for a read.
                  result:
                    $schema: https://json-schema.org/draft/2020-12/schema
                    anyOf:
                      - type: object
                        properties:
                          user:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                                pattern: >-
                                  ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                              primaryEmail:
                                type:
                                  - string
                                  - 'null'
                              primaryPhone:
                                type:
                                  - string
                                  - 'null'
                              isNew:
                                type: boolean
                            required:
                              - id
                              - primaryEmail
                              - primaryPhone
                              - isNew
                            additionalProperties: {}
                          session:
                            type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                                pattern: >-
                                  ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                              accessToken:
                                type: string
                              accessExpiresAt:
                                type: string
                                format: date-time
                                pattern: >-
                                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                              refreshToken:
                                type: string
                              refreshExpiresAt:
                                type: string
                                format: date-time
                                pattern: >-
                                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                            required:
                              - id
                              - accessToken
                              - accessExpiresAt
                              - refreshToken
                              - refreshExpiresAt
                            additionalProperties: {}
                        required:
                          - user
                          - session
                        additionalProperties: {}
                      - type: object
                        properties:
                          mfa:
                            type: object
                            properties:
                              required:
                                type: boolean
                                const: true
                              mfaToken:
                                type: string
                              expiresAt:
                                type: string
                                format: date-time
                                pattern: >-
                                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                              methods:
                                type: array
                                items:
                                  type: string
                            required:
                              - required
                              - mfaToken
                              - expiresAt
                              - methods
                            additionalProperties: {}
                        required:
                          - mfa
                        additionalProperties: {}
                required:
                  - activityId
                  - result
        '400':
          description: invalid_input or invalid_json
        '401':
          description: unauthenticated
        '403':
          description: forbidden
        '404':
          description: not_found
        '409':
          description: 'conflict: idempotency_mismatch, email_taken, last_key'
        '413':
          description: body_too_large
        '429':
          description: rate_limited
      security:
        - bearer: []
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: >-
        A Lath API key: lath_live_sk… or lath_test_sk… on a server,
        lath_live_pk… or lath_test_pk… in a browser.

````