Enrollments & FIDO2 payments
An enrollment links a payer's device to their account using a FIDO2 passkey. Once authorised, the payer can pay again without a bank redirect — just a biometric prompt on their own device.
Create an enrollment
import { createEnrollment } from '@lina-openx/web-lina-pay-sdk'
const enrollment = await createEnrollment(
{ subtenantId: 'your-subtenant-id', subtenantSecret: 'your-subtenant-secret' },
{
organisationId: 'org-uuid',
authorisationServerId: 'auth-uuid',
enrollment: {
document: '12345678901', // payer's CPF
deviceName: "Jane's iPhone",
debtor: {
accountNumber: '123456',
accountIssuer: '0001',
accountIspb: '12345678',
accountType: 'CACC',
},
},
redirectUri: 'https://example.com/enrollment-callback',
},
)
window.location.href = enrollment.redirectUrlRegister the device (after the callback)
After the payer authorizes at their bank and is redirected back with
state/code/idToken:
import { registerDevice } from '@lina-openx/web-lina-pay-sdk'
const registered = await registerDevice(
{ subtenantId: 'your-subtenant-id', subtenantSecret: 'your-subtenant-secret' },
{ state, code, idToken, tenantId: 'your-subtenant-id' },
)
console.log(registered.enrollmentId, registered.status) // AUTHORISED once readyList and revoke enrollments
import { getEnrollmentList, revokeEnrollment } from '@lina-openx/web-lina-pay-sdk'
const { enrollments } = await getEnrollmentList(credentials, '12345678901')
enrollments.forEach((e) => console.log(e.enrollmentId, e.status))
await revokeEnrollment(credentials, 'enrollment-id')Pay with an enrollment
Once an enrollment is AUTHORISED, pay without redirecting the payer to
their bank — the SDK triggers the device's biometric prompt and completes
the payment in one call:
import { createPaymentWithEnrollment } from '@lina-openx/web-lina-pay-sdk'
const payment = await createPaymentWithEnrollment(credentials, {
enrollmentId: 'active-enrollment-id',
organisationId: 'org-uuid',
authorisationServerId: 'auth-uuid',
payment: {
value: 1500.50,
details: 'Service payment',
externalId: 'payment-123',
redirectUri: 'https://example.com/payment-success',
cpfCnpj: '12345678901',
creditor: {
name: 'Beneficiary Company',
personType: 'PESSOA_JURIDICA',
cpfCnpj: '12345678000190',
accountNumber: '123456',
accountIssuer: '0001',
accountPixKey: 'company@example.com',
accountIspb: '12345678',
accountType: 'CACC',
},
},
fidoSignOptions: {
rp: 'app.linaopenx.com.br',
platform: 'WEB',
},
})
console.log(payment.id, payment.consentId)Next steps
- Linked Journey — create the Data Link consent and the enrollment in a single call.
- Error handling —
LinaPayErrorand validation failures.