Passwordless is a form of authentication that doesn't require users to provide their username during login. WebAuthn is a complex standard with many moving parts, including the FIDO2 specifications. Since they aren't stored in the authenticator, the Relying Party has to send the key handles back. There can be no credential selection without talking to the RP.

10m read timeFrom goteleport.com
Post cover image
Table of contents
WebAuthn recapBuilding block #1: discoverable credentialsBuilding block #2: user verificationBuilding block #3: attestationPasswordless authentication flowSecurity(Some) Topics we left outClosing thoughts
2 Comments

Sort: