• 12 Dec, 2025 *

This is the first post in a multi-part series covering passkeys (or WebAuthn). You’ve likely encountered passkeys in the wild at some point. They are ubiquitous and for good reason, they are one form of phishing-resistant authentication, definitely the most popular one.

Table of Contents

  • Introduction (current)
  • The Registration Ceremony
  • The Authentication Ceremony
  • FIDO Metadata
  • The Packed Attestation
  • Implementing a Virtual Authenticator

(Note: will be updated as more posts are completed)

So what in the world is a passkey? Simply put, it is a public / private key pair stored on an authenticator tied to a specific website and possibly user. There are multiple kinds of authentic…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help