API Documentation

WiraPass Developer Documentation

Add phone sign-in approvals and WiraPass backup codes to your system, through a Duo-compatible Auth API or a simple JSON API.

Documentation Pages

WiraPass adds a second step when people sign in to your system. Once the password checks out, the user approves the sign-in on their phone, or types a backup code from the WiraPass app.

How WiraPass Fits into a Sign-In

  1. The user types an email and password into your system, and your system checks them as usual. WiraPass never sees that password.
  2. Your system asks WiraPass whether this user can be asked for approval (preauth). Users are identified by the email they use in WiraPass.
  3. WiraPass sends a request to the user's approval phones that are signed in to the WiraPass app (auth). The screen shows the name of your system, the title of the request and the details you send, such as the IP address.
  4. The user taps Approve, Deny or Not me. Approve is signed by the device key on the phone, so it cannot be forged from outside. Not me also pauses new requests from your system for that user for 15 minutes.
  5. Your system reads the result (auth_status) and lets the user in only when it is allow.

When the phone has no internet connection, the user opens the WiraPass app and reads the 6-digit backup code. Your system checks it with factor=passcode. Each code works only once.

Two APIs, One Approval System

Both follow the same rules: requests only go to phones signed in to WiraPass, at most 3 waiting requests per user, and a 15-minute pause after Not me. One integration may use both APIs.

Getting Integration Keys

For now, integration keys are created by the WiraPass operator. Email support@wiracode.com with:

  • the name of your system, exactly as users should see it on their phone (at most 80 characters);
  • a technical contact;
  • a rough number of users and requests per minute.

You will receive:

ValueFormatFor
Integration key (ikey)DI and 18 upper-case letters or digitsAuth API
Secret key (skey)40 letters and digitsAuth API
API hostnameauth.wiracode.comAuth API
Simple API keywpk_…Simple JSON API

The secret key and the API key are shown only once. Keep them like passwords, on your server, never in a web page or a mobile app. If one leaks, ask for a new one: the old one stops working at once.

Next Steps

OpenAPI Specification

Both APIs are described in one OpenAPI 3.1 document at https://auth.wiracode.com/openapi.json. You can open it in Swagger Editor, Postman or a client generator.

Duo is a trademark of Cisco. WiraPass is not affiliated with Duo or Cisco and only offers API compatibility.