Skip to main content
ResetPasswordMfaWebAuthnRoamingChallengeMembers
Example

Properties

Access to the specific properties and data of the reset-password-mfa-webauthn-roaming-challenge screen, including WebAuthn publicKey challenge options and the showRememberDevice flag.

Methods

Promise<void>
Reports a client-side WebAuthn API error (from navigator.credentials.get()) to Auth0. This method should be used when useSecurityKey() (or a manual navigator.credentials.get() call) fails due to a browser-side WebAuthn issue (e.g., NotAllowedError if the user cancels the prompt, NotFoundError if no matching authenticator is found, or a timeout). It submits the error details with action: "showError::{errorDetailsJsonString}" and an empty response.A promise that resolves when the error report is submitted. Auth0 may re-render the page with error information or redirect.

Throws

Throws an error if the form submission fails (e.g., network error, invalid state).
Promise<void>
Allows the user to opt-out of the WebAuthn roaming challenge and select a different MFA method. This action submits action: "pick-authenticator" to Auth0, which should navigate the user to an MFA factor selection screen.A promise that resolves when the ‘pick-authenticator’ action is submitted.

Throws

Throws an error if the form submission fails.
Promise<void>
Initiates the WebAuthn assertion process (security key challenge). This method will internally call navigator.credentials.get() using the challenge provided in screen.publicKey. On successful interaction with the security key, it submits the resulting PublicKeyCredential to Auth0 with action: "default".A promise that resolves when the verification attempt is submitted. A successful operation typically results in a redirect by Auth0.

Throws

Throws an error if screen.publicKey is missing, if navigator.credentials.get() fails (e.g., user cancellation, no authenticator found), or if the form submission to Auth0 fails. It’s recommended to catch these errors and potentially use showError() to report WebAuthn API specific issues.