Skip to main content
POST
Start a passkey recovery for a signer

Authorizations

x-api-key
string
header
required

Headers

Idempotency-Key
string
required

Caller-generated unique key that lets the server safely replay this request. The original response is returned for 30 days on any retry with the same key from the same organization, with the response header Idempotency-Replayed: true. Required on every state-changing money-moving or resource-creating POST.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9_.:-]{1,128}$
Example:

"01J7B3K2X9M8N5P6Q7R8S9T0V1"

Path Parameters

customerId
string
required
Example:

"cus_1A2b3C4d5E6f7G8h9I0jKl"

signerId
string
required
Example:

"wsg_1A2b3C4d5E6f7G8h9I0jKl"

Response

signerId
string
required

The signer who lost a passkey

Pattern: ^wsg_[0-9A-Za-z]{22}$
ceremonyId
string
required

Recovery ceremony. The wallet_ceremony.* events of type recovery carry the same id.

verificationUrl
string<uri>
required

Conduit-hosted recovery link to route the signer to. The signer creates the new passkey and confirms the change with the passkey they kept.

Example:

"https://app.conduit.financial/verify/mtQzSU2hdy0DuZ6za2IHIoVDgXzshrFtN38kMULRDFw"

expiresAt
string<date-time>
required

When the link expires. Call the endpoint again for a fresh link.

Example:

"2026-01-15T09:30:00.000Z"