Auth0 My Account API: Passkey add/registration (EA) scopes + plan requirements?

What is this discussion about in one brief sentence?
Questions about the Early Access permissions/scopes for adding/registering passkeys via the Auth0 My Account (Account) API, and whether those permissions are available on free tenants or require a paid plan.

Hi Auth0 Community,

I’m implementing a flow where end users can manage their own authentication methods, and I’m specifically looking at adding/registering passkeys via the My Account (Account) API (Connected Accounts–style “me:” scopes and related endpoints).

I have a few questions about the Early Access capability for “passkey add/registration” through the Account API:

  1. Which exact scopes/permissions are required to enable end users to add/register a passkey via the Account API?

    • If there are multiple scopes depending on the endpoint, could you list the recommended minimum set?
  2. Is this feature still Early Access, and if so, how can a tenant get access enabled (self-serve toggle vs. request/support ticket)?

  3. Plan / pricing question:

    • Can these Early Access scopes/features be enabled on a Free Auth0 tenant?

    • If not, which paid plan is required (e.g., B2C Essentials / Professional / Enterprise, etc.)?

  4. Are there any known limitations (supported regions, Universal Login requirements, passkey policy prerequisites, RP ID constraints, etc.) when using the Account API for passkey registration?

Any guidance, docs, or examples would be greatly appreciated.

Thanks!

Hi @tomitasho

Welcome to the Auth0 Community!

Thank you for posting your question.

All the details regarding the specyfic scope or permissions during stages of user enrollment you find in the documentation for My Account API → My Account API and in the My Account API explorer → Welcome to Auth0 Docs - Auth0 Docs

To access the feature in the current Early Access state you will need to on the enterprise agreement and contact dedicated to your account TAM. I can’t provide you with information when this Authentication Methods managment with My Account API will be available in the General Availability but I will make sure to update you as soon as I have any details.

In terms of the known limitation apart from the regular passkey enablment limitation it is recommended to use the custom domains.

Thanks!
Dawid

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.