Identify
curl --request POST \
--url https://api.example.com/api/v1/auth/identify \
--header 'Content-Type: application/json' \
--data '
{
"email": "<string>"
}
'const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({email: '<string>'})
};
fetch('https://api.example.com/api/v1/auth/identify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.example.com/api/v1/auth/identify"
payload = { "email": "<string>" }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"method": "<string>",
"passkey_options": {},
"twofa_required": false,
"fallbacks": []
}Auth
Identify
Decide the best auth method for this email.
Returns one of:
{ method: "passkey", passkey_options: {...} } user has a passkey
{ method: "password", twofa_required: bool } user has a usable password
{ method: "magic_link_sent" } magic-link-only user (link sent)
{ method: "no_account" } no account exists for this email
Preference order: passkey > password > magic-link (per "passkey wins" UX decision).
The "no_account" branch does NOT send anything — the caller decides whether
to surface a signup CTA (login page) or proceed with signup (signup page).
Rate-limited per IP (10/min) to prevent enumeration sweeps.
POST
/
api
/
v1
/
auth
/
identify
Identify
curl --request POST \
--url https://api.example.com/api/v1/auth/identify \
--header 'Content-Type: application/json' \
--data '
{
"email": "<string>"
}
'const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({email: '<string>'})
};
fetch('https://api.example.com/api/v1/auth/identify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.example.com/api/v1/auth/identify"
payload = { "email": "<string>" }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"method": "<string>",
"passkey_options": {},
"twofa_required": false,
"fallbacks": []
}