[{"data":1,"prerenderedAt":74},["ShallowReactive",2],{"doc:\u002Freference\u002Fattestation-challenge":3},{"page":4,"toc":70,"updated":73},{"path":5,"title":6,"seoTitle":7,"description":8,"blocks":9,"examples":59},"\u002Freference\u002Fattestation-challenge","Request an attestation challenge","Attestation Challenge: POST \u002Fattestation\u002Fchallenge","Issue a one-time, five-minute challenge that the Android SDK has the device keystore attest to, proving the report is fresh.",[10,15,18,22,24,29,39,41,44],{"type":11,"method":12,"path":13,"auth":14},"endpoint","POST","\u002Fapi\u002Fv1\u002Fattestation\u002Fchallenge","public",{"type":16,"text":17},"p","Issues a random challenge bound to your organization and SDK key. The [Android SDK](\u002Fdocs\u002Fsdks\u002Fandroid#hardware-backed-attestation) requests one before collecting, has the device's hardware keystore attest to it, and includes the attestation in its identify request. The server checks it and consumes the challenge, so an attestation cannot be replayed.",{"type":19,"tone":20,"text":21},"callout","note","The Android SDK calls this endpoint automatically. See [mobile app attestation](\u002Fdocs\u002Fmobile-attestation).",{"type":16,"text":23},"The request has no body.",{"type":25,"level":26,"text":27,"id":28},"heading",2,"Response","response",{"type":30,"fields":31},"fields",[32,36],{"name":33,"type":34,"text":35},"challenge","string","32 random bytes, base64-encoded.",{"name":37,"type":34,"text":38},"expires_at","When the challenge stops being accepted: five minutes after it was issued.",{"type":16,"text":40},"Each challenge can be used once. Challenges are free.",{"type":25,"level":26,"text":42,"id":43},"Errors","errors",{"type":45,"columns":46,"rows":50},"table",[47,48,49],"Status","Code","When",[51,55],[52,53,54],"`401`","`unauthorized`","The key did not authenticate.",[56,57,58],"`503`","`service_unavailable`","A challenge could not be issued just now.",{"request":60,"response":65},[61],{"label":62,"lang":63,"code":64},"cURL","bash","curl -X POST \"https:\u002F\u002Fus.api.fingerly.io\u002Fapi\u002Fv1\u002Fattestation\u002Fchallenge\" \\\n  -H \"x-api-key: fly_pk_us_production_…\" \\\n  -H \"x-fingerly-sdk-platform: android\"",[66],{"label":67,"lang":68,"code":69},"200","json","{\n  \"challenge\": \"q8Xv0bJ3c2Vj3kQm1s9Qe2Ww5rT7yU8iO1pA3sD5fG0=\",\n  \"expires_at\": \"2026-09-16T09:46:12Z\"\n}",[71,72],{"id":28,"text":27,"level":26},{"id":43,"text":42,"level":26},"2026-09-17T08:28:36.000Z",1789667797857]