Passwordless is a form of authentication that doesn't require users to provide their username during login. WebAuthn is a complex standard with many moving parts, including the FIDO2 specifications. Since they aren't stored in the authenticator, the Relying Party has to send the key handles back. There can be no credential selection without talking to the RP.
Table of contents
WebAuthn recapBuilding block #1: discoverable credentialsBuilding block #2: user verificationBuilding block #3: attestationPasswordless authentication flowSecurity(Some) Topics we left outClosing thoughts2 Comments
Sort: