Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
A W3C standard that lets websites sign users in with public-key credentials held by an authenticator instead of with passwords.
WebAuthn defines how a website asks a browser to create and use credentials, and what the authenticator returns: a public key, a signature, and data about the site and the user check. It is the web half of FIDO2; the other half, CTAP, covers how a browser talks to an external authenticator. On Android 14 and newer, browsers use the platform's Credential Manager, and a passkey provider such as HostSpica Passkey answers the request. WebAuthn Level 2 is a W3C Recommendation and Level 3 is in draft.
A discoverable WebAuthn credential that lets you sign in to a site with a fingerprint, face or screen lock instead of a password.
A WebAuthn credential the authenticator can find by site alone, so the user does not have to type a username first. Also called a resident key.
Our expert team can help you leverage WebAuthn (Web Authentication) in your project.
Get Free Consultation