Skip to main content
POST
Initiate Cross-DUID Re-identification by MPxN

Authorizations

Authorization
string
header
required

JWT from GET /auth/token. Pass as Authorization: Bearer <token>. Expires after 7200s.

Body

application/json
mpxn
string
required

Meter Point Administration Number (MPAN) or Meter Point Reference Number (MPRN).

Pattern: ^(?:[0-9A-HJ-NPR-Z]{2}[0-9]{8,10}|[0-9]{10})$
Example:

"1234567890123"

method
enum<string>
required

The re-identification method to use.

magic-link — single-step. The register dispatches a signed link to the stored email address. Optionally supply redirect-url to send the customer back to the Data User's app after clicking; otherwise the customer lands on central.consent. Poll or check GET /identity-records/{ir}/re-identify/{token-ref} to confirm.

passkey-assert — two-step redirect. The response contains a passkey-redirect with a short-lived URL to id.central.consent. Redirect the customer there; the register runs the WebAuthn assertion against the stored public key on its own origin, then redirects back with ?dar-passkey-token={token-ref}. Call GET /identity-records/{ir}/re-identify/{token-ref} once to confirm.

passkey-register — two-step redirect for new device enrolment. Same flow as passkey-assert but runs a registration ceremony instead of assertion. Stores a new public key credential on the Identity Record and confirms re-identification on success.

Available options:
magic-link,
passkey-assert,
passkey-register
redirect-url
string<uri> | null
passkey-return-url
string<uri> | null

Response

Re-identification flow initiated. Customer has been challenged.

response
object
required
method
enum<string>
required

The re-identification method to use.

magic-link — single-step. The register dispatches a signed link to the stored email address. Optionally supply redirect-url to send the customer back to the Data User's app after clicking; otherwise the customer lands on central.consent. Poll or check GET /identity-records/{ir}/re-identify/{token-ref} to confirm.

passkey-assert — two-step redirect. The response contains a passkey-redirect with a short-lived URL to id.central.consent. Redirect the customer there; the register runs the WebAuthn assertion against the stored public key on its own origin, then redirects back with ?dar-passkey-token={token-ref}. Call GET /identity-records/{ir}/re-identify/{token-ref} once to confirm.

passkey-register — two-step redirect for new device enrolment. Same flow as passkey-assert but runs a registration ceremony instead of assertion. Stores a new public key credential on the Identity Record and confirms re-identification on success.

Available options:
magic-link,
passkey-assert,
passkey-register

Populated for magic-link method; null otherwise.

passkey
object | null

Populated for passkey-assert and passkey-register methods; null for magic-link. Contains the redirect URL to id.central.consent where the WebAuthn ceremony takes place.

Last modified on March 25, 2026