> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spritz.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Prepare add auth method

> Prepares a Turnkey activity for adding a new auth method (passkey, OAuth, or email). When a new method must be added, returns `status: "intent_required"` and an intent the wallet must stamp. When the same OAuth/email method already exists, returns `status: "already_exists"` with the existing method — no commit is needed.



## OpenAPI

````yaml https://platform.spritz.finance/openapi.json post /v1/wallet-kit/auth-methods/intents
openapi: 3.0.3
info:
  title: Spritz Finance API
  version: 1.0.0
  description: API for the Spritz Finance platform with RFC 9457 error handling
servers:
  - url: https://platform.spritz.finance
    description: Production
  - url: https://sandbox.spritz.finance
    description: Sandbox
security: []
tags:
  - name: Users
    description: User management endpoints
  - name: Bank Accounts
    description: Manage bank accounts for off-ramp destinations
  - name: Bills
    description: Manage bill pay accounts
  - name: Cards
    description: Spritz-issued debit cards
  - name: Auto-Ramp Accounts
    description: Virtual bank accounts that automatically convert fiat deposits to crypto
  - name: Spritz App
    description: >-
      Endpoints used by the Spritz app and internal SDKs. Excluded from the
      public partner spec.
paths:
  /v1/wallet-kit/auth-methods/intents:
    post:
      tags:
        - Wallet Kit
      summary: Prepare add auth method
      description: >-
        Prepares a Turnkey activity for adding a new auth method (passkey,
        OAuth, or email). When a new method must be added, returns `status:
        "intent_required"` and an intent the wallet must stamp. When the same
        OAuth/email method already exists, returns `status: "already_exists"`
        with the existing method — no commit is needed.
      operationId: postV1Wallet-kitAuth-methodsIntents
      requestBody:
        description: >-
          Prepare request for adding an auth method. Discriminated by `kind`.
          Email requires a prior call to the email-start flow to obtain `otpId`.
        required: true
        content:
          application/json:
            schema:
              description: >-
                Prepare request for adding an auth method. Discriminated by
                `kind`. Email requires a prior call to the email-start flow to
                obtain `otpId`.
              anyOf:
                - type: object
                  properties:
                    kind:
                      type: string
                      enum:
                        - passkey
                    challenge:
                      minLength: 1
                      description: Passkey/WebAuthn challenge produced by the client SDK.
                      type: string
                    label:
                      minLength: 1
                      description: Optional nickname for this passkey.
                      type: string
                  required:
                    - kind
                    - challenge
                - type: object
                  properties:
                    kind:
                      anyOf:
                        - type: string
                          enum:
                            - google
                        - type: string
                          enum:
                            - apple
                    oidcToken:
                      minLength: 1
                      description: >-
                        OIDC ID token issued by Google or Apple after a
                        successful sign-in flow on the client.
                      type: string
                    label:
                      minLength: 1
                      description: Optional label for this method.
                      type: string
                  required:
                    - kind
                    - oidcToken
                - type: object
                  properties:
                    kind:
                      type: string
                      enum:
                        - email
                    email:
                      minLength: 1
                      format: email
                      description: >-
                        Email address to register. Must match the OTP start
                        email.
                      type: string
                    otp:
                      minLength: 1
                      description: >-
                        One-time passcode delivered to `email` by the
                        email-start flow.
                      type: string
                    otpId:
                      minLength: 1
                      description: >-
                        OTP identifier returned by the email-start commit
                        endpoint.
                      type: string
                    targetPublicKey:
                      minLength: 1
                      description: >-
                        Turnkey iframe public key produced by the client SDK
                        (e.g. `authIframeClient.iframePublicKey`).
                      type: string
                    label:
                      minLength: 1
                      description: Optional label for this method.
                      type: string
                  required:
                    - kind
                    - email
                    - otp
                    - otpId
                    - targetPublicKey
          application/x-www-form-urlencoded:
            schema:
              description: >-
                Prepare request for adding an auth method. Discriminated by
                `kind`. Email requires a prior call to the email-start flow to
                obtain `otpId`.
              anyOf:
                - type: object
                  properties:
                    kind:
                      type: string
                      enum:
                        - passkey
                    challenge:
                      minLength: 1
                      description: Passkey/WebAuthn challenge produced by the client SDK.
                      type: string
                    label:
                      minLength: 1
                      description: Optional nickname for this passkey.
                      type: string
                  required:
                    - kind
                    - challenge
                - type: object
                  properties:
                    kind:
                      anyOf:
                        - type: string
                          enum:
                            - google
                        - type: string
                          enum:
                            - apple
                    oidcToken:
                      minLength: 1
                      description: >-
                        OIDC ID token issued by Google or Apple after a
                        successful sign-in flow on the client.
                      type: string
                    label:
                      minLength: 1
                      description: Optional label for this method.
                      type: string
                  required:
                    - kind
                    - oidcToken
                - type: object
                  properties:
                    kind:
                      type: string
                      enum:
                        - email
                    email:
                      minLength: 1
                      format: email
                      description: >-
                        Email address to register. Must match the OTP start
                        email.
                      type: string
                    otp:
                      minLength: 1
                      description: >-
                        One-time passcode delivered to `email` by the
                        email-start flow.
                      type: string
                    otpId:
                      minLength: 1
                      description: >-
                        OTP identifier returned by the email-start commit
                        endpoint.
                      type: string
                    targetPublicKey:
                      minLength: 1
                      description: >-
                        Turnkey iframe public key produced by the client SDK
                        (e.g. `authIframeClient.iframePublicKey`).
                      type: string
                    label:
                      minLength: 1
                      description: Optional label for this method.
                      type: string
                  required:
                    - kind
                    - email
                    - otp
                    - otpId
                    - targetPublicKey
          multipart/form-data:
            schema:
              description: >-
                Prepare request for adding an auth method. Discriminated by
                `kind`. Email requires a prior call to the email-start flow to
                obtain `otpId`.
              anyOf:
                - type: object
                  properties:
                    kind:
                      type: string
                      enum:
                        - passkey
                    challenge:
                      minLength: 1
                      description: Passkey/WebAuthn challenge produced by the client SDK.
                      type: string
                    label:
                      minLength: 1
                      description: Optional nickname for this passkey.
                      type: string
                  required:
                    - kind
                    - challenge
                - type: object
                  properties:
                    kind:
                      anyOf:
                        - type: string
                          enum:
                            - google
                        - type: string
                          enum:
                            - apple
                    oidcToken:
                      minLength: 1
                      description: >-
                        OIDC ID token issued by Google or Apple after a
                        successful sign-in flow on the client.
                      type: string
                    label:
                      minLength: 1
                      description: Optional label for this method.
                      type: string
                  required:
                    - kind
                    - oidcToken
                - type: object
                  properties:
                    kind:
                      type: string
                      enum:
                        - email
                    email:
                      minLength: 1
                      format: email
                      description: >-
                        Email address to register. Must match the OTP start
                        email.
                      type: string
                    otp:
                      minLength: 1
                      description: >-
                        One-time passcode delivered to `email` by the
                        email-start flow.
                      type: string
                    otpId:
                      minLength: 1
                      description: >-
                        OTP identifier returned by the email-start commit
                        endpoint.
                      type: string
                    targetPublicKey:
                      minLength: 1
                      description: >-
                        Turnkey iframe public key produced by the client SDK
                        (e.g. `authIframeClient.iframePublicKey`).
                      type: string
                    label:
                      minLength: 1
                      description: Optional label for this method.
                      type: string
                  required:
                    - kind
                    - email
                    - otp
                    - otpId
                    - targetPublicKey
      responses:
        '200':
          description: >-
            Prepare response. Branch on `status`: `intent_required` requires
            stamping + commit; `already_exists` returns the existing method
            directly.
          content:
            application/json:
              schema:
                description: >-
                  Prepare response. Branch on `status`: `intent_required`
                  requires stamping + commit; `already_exists` returns the
                  existing method directly.
                anyOf:
                  - description: >-
                      A new auth method is being added. The wallet must stamp
                      `intent.activityBody` and call commit with the returned
                      `intentId` and stamp.
                    type: object
                    properties:
                      status:
                        type: string
                        enum:
                          - intent_required
                      intent:
                        description: >-
                          Prepared activity that the embedded wallet must stamp
                          before commit.
                        type: object
                        properties:
                          intentId:
                            description: >-
                              Single-use intent identifier returned by prepare.
                              Pass back to commit alongside the user's stamp.
                              TTL is 60 seconds.
                            type: string
                          activityBody:
                            description: >-
                              Turnkey activity body bytes for the wallet to
                              stamp. Sign with the user's WebAuthn authenticator
                              and submit the stamp via the matching commit
                              endpoint.
                            type: string
                          timestampMs:
                            description: >-
                              Unix-millisecond timestamp the activity body was
                              issued at. Pass through verbatim when stamping.
                            type: string
                          expiresAt:
                            format: date-time
                            description: >-
                              ISO 8601 timestamp at which the prepared intent
                              expires (60s after issue).
                            type: string
                        required:
                          - intentId
                          - activityBody
                          - timestampMs
                          - expiresAt
                    required:
                      - status
                      - intent
                  - description: >-
                      The OAuth/email method is already registered. No commit is
                      needed; the existing method is returned.
                    type: object
                    properties:
                      status:
                        type: string
                        enum:
                          - already_exists
                      data:
                        description: >-
                          An authentication method registered on the user's
                          embedded wallet sub-organization.
                        type: object
                        properties:
                          id:
                            description: Stable identifier for the auth method.
                            type: string
                          kind:
                            description: >-
                              Authentication method kind. `passkey` is a
                              WebAuthn authenticator on this device;
                              `google`/`apple` are OIDC tokens; `email` is a
                              verified email address used for OTP login.
                            anyOf:
                              - type: string
                                enum:
                                  - passkey
                              - type: string
                                enum:
                                  - google
                              - type: string
                                enum:
                                  - apple
                              - type: string
                                enum:
                                  - email
                          label:
                            description: >-
                              Human-readable label for the method (e.g., the
                              email address, OAuth account label, or passkey
                              nickname).
                            type: string
                          addedAt:
                            format: date-time
                            description: Timestamp when the method was added (ISO 8601).
                            type: string
                          isPrimary:
                            description: >-
                              Whether this method is the user's primary method.
                              The primary method cannot be removed without first
                              promoting another.
                            type: boolean
                        required:
                          - id
                          - kind
                          - label
                          - addedAt
                          - isPrimary
                    required:
                      - status
                      - data
        '401':
          description: Response for status 401
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 401
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                    example: Bearer token required
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  realm:
                    description: The authentication realm
                    type: string
                    example: API
                  scope:
                    description: The required scope for this resource
                    type: string
                    example: read:users
                required:
                  - title
                  - status
                additionalProperties: false
        '409':
          description: Response for status 409
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
        '429':
          description: Response for status 429
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
        '500':
          description: Response for status 500
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Cognito JWT token for regular user authentication

````