Security and sign-in
Complete sign-in with a passkey
POST
/api/auth/mfa/passkey#Authentication
Public
No credential. Public routes are rate limited per address.
Carries the short-lived MFA ticket that POST /api/auth/login returned, not a session.