curl --request DELETE \
--url https://api.mnemom.ai/v1/auth/passkeys/{credential_id} \
--cookie mnemom_session={
"ok": true
}Requires aal2. Deleting a passkey does not affect other passkeys or the password/MFA fallback; those remain usable.
curl --request DELETE \
--url https://api.mnemom.ai/v1/auth/passkeys/{credential_id} \
--cookie mnemom_session={
"ok": true
}HttpOnly, Secure, SameSite=Lax cookie issued by /v1/auth/sign-in (or the SSO / email-callback flows). The value is an AES-256-GCM-encrypted blob of {access_token, refresh_token, issued_at, auth_method}. Browser clients include this automatically with credentials: "include".
Passkey removed.