Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
Evidence provided at registration about the authenticator that created a key, such as a certificate chain showing the key lives in secure hardware.
When a passkey is created, the authenticator can include an attestation statement. Android's android-key format carries the certificate chain that Android's Keystore produced for the new key, ending at Google's hardware attestation root. A relying party can check that chain to learn that the key was generated in the phone's secure hardware. Most consumer sites ask for no attestation or ignore it. It matters to organisations that want to allow only certain devices. An authenticator model identifier called the AAGUID accompanies it; HostSpica Passkey's is self-assigned and not registered with the FIDO Alliance.
A discoverable WebAuthn credential that lets you sign in to a site with a fingerprint, face or screen lock instead of a password.
The Android system service that creates cryptographic keys and uses them on an app's behalf without ever giving the app the raw key.
A separate tamper-resistant secure chip in some Android phones that can store keys and perform cryptography apart from the main processor.
Our expert team can help you leverage Attestation (WebAuthn) in your project.
Get Free Consultation