Test authentication before production
Verify the happy path and the failure paths before real users hit them.
Before relying on PTERI authentication in production, verify with a non-production account:
- The happy path. Request authentication, approve the challenge with biometrics, confirm your backend receives a valid, verified session — see how authentication works.
- An expired challenge. Let a challenge time out on purpose and confirm your app handles the resulting error gracefully rather than hanging — see "challenge expired" or "invalid signature".
- A declined or failed signature. Confirm your app shows a clear retry path rather than a dead end.
- MFA/device verification, if you use it — see MFA and device verification — including what happens if the device is offline.
Once these all behave the way you expect, move on to the rest of the production readiness checklist.