Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Implement passkeys as a server-verified WebAuthn flow: your server creates a fresh challenge, the browser asks an authenticator to create or use a credential, and your server verifies the returned credential before changing account state or creating a session. The authenticator manages the private key; your application stores the public key. Passkeys improve sign-in UX, but recovery, credential enrollment and session security still belong in your application’s threat model.

This guide follows the W3C Web Authentication Level 3 Recommendation, published August 25, 2026. Level 4 is a working draft, not the deployed Recommendation.

What a passkey is—and what your application stores

A passkey is a discoverable FIDO credential based on public-key cryptography. It is scoped to a relying party (RP)—your application’s configured identity—and used through a client platform such as a browser and authenticator. The client mediates access to the authenticator, and user consent is part of the process.

During registration, the authenticator creates or manages the private-key operations. Your server receives the public key and credential ID and stores them against the account. During sign-in, the authenticator signs a fresh challenge; your server checks that signature with the stored public key. Your server never receives a user’s biometric template. Local user verification authorizes use of the credential; biometric data is not disclosed to the relying party.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Elebase USB to USB C Adapter for iPhone 18 Pro Max,USBC Car Charger Adapter
  • Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
  • Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
  • Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
  • Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
  • 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.

Discoverable credentials let someone begin a sign-in without first typing a username. In that flow, the credential can identify the account through a user handle. The W3C sets a 64-byte maximum for the handle and says it must be an opaque byte sequence that contains no personally identifying information. Do not encode an email address or other account data in it.

Choose the sign-in and authenticator policy

Decide how passkeys fit your current login and security policy before writing the ceremony. Passkey availability and authenticator behavior vary by platform, so avoid assuming every user has the same device capabilities.

Choice What it means Design consideration
Synced multi-device passkey A passkey that a user can access on more than one device through the platform’s synchronization mechanism. Convenient across devices; plan account recovery and credential removal for users who lose access to the platform account.
Device-bound credential or security key A credential held by a particular authenticator, including a roaming physical security key. Can suit environments that require organizational control or a specific assurance policy, but users need an additional compatible authenticator and a replacement plan.
Identifier-first UX The user enters an identifier before the application requests a credential. Can support a mix of passkey, non-discoverable credential and password sign-in paths.
Authentication-method-first UX The user starts with an option such as “Sign in with a passkey”; the client can offer discoverable credentials. Can avoid asking for a username when discoverable credentials are available. Keep an accessible fallback for users who cannot use that route.

FIDO Alliance deployment guidance discusses these UX choices and the portability and control trade-offs. Choose based on your users, device environment and assurance requirements rather than treating one credential type as universally best.

Rank #2
Anker USB-C Hub, 5-in-1 USB Hub for Laptops, 4K HDMI Multiport Adapter
  • 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
  • 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
  • Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
  • 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
  • What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.

Set user verification intentionally

WebAuthn offers required, preferred and discouraged user-verification preferences. “Required” asks for verification such as a local PIN or biometric before credential use; it is not a request for the RP to collect biometric data. Whether to require it depends on the application’s risk and user experience. Check what your server library and target platforms support, and enforce the server-side flags that match your policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Implement passkey registration

Registration binds a new public-key credential to an account. Require an authenticated session or apply your application’s account-creation policy before allowing enrollment; otherwise, an attacker who can reach an account may bind their own credential.

  1. Start an enrollment request on the server. Generate a fresh cryptographically secure challenge. Build public-key creation options with the RP ID and name, the account’s stable opaque user ID, the user name and display name, supported parameters, the challenge, excluded existing credential IDs where appropriate, and your authenticator, discoverability and user-verification preferences.
  2. Send options to the client. Your server-side FIDO/WebAuthn library should construct the options and later verify the response. Return the challenge in session-bound or otherwise securely associated state so the server can retrieve the expected value during verification.
  3. Ask the browser to create the credential. Convert the server’s JSON into the browser’s WebAuthn representation as required by your client and library, then call navigator.credentials.create({ publicKey }). The client mediates the authenticator interaction and consent.
  4. Post the result to the server. Serialize the credential response in the format expected by your backend library. Do not treat a successful browser callback as proof that enrollment is valid.
  5. Verify and persist. Verify the expected challenge, exact expected origin, RP ID and relevant user-presence, user-verification and attestation policy. Only after verification succeeds, store at least the credential ID, public key and account association, plus counter or implementation metadata required by your library. Return success to the user only after persistence succeeds.

Credential creation and response serialization APIs differ across web frameworks and library versions. Use a maintained server-side FIDO library rather than hand-rolling WebAuthn parsing, signature handling or cryptography. Google’s server-side guide likewise advises using a server-side FIDO library for options construction and verification.

Rank #3
Sale
Anker USB C Hub, 7in1 Multi-Port USB Adapter, 4K@60Hz USBC to HDMI Splitter
  • Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
  • Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
  • Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
  • Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
  • What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.

Implement sign-in and verify the assertion

Authentication is a separate ceremony. It must use a new challenge, not the challenge from registration or a previous login attempt.

  1. Create a one-time challenge. Generate a cryptographically secure value for each attempt, bind it to the session or transaction, and give it a short policy-defined validity window. Google’s implementation guide suggests five minutes as a default and up to ten minutes within its recommended range; those are guide recommendations, not WebAuthn protocol constants.
  2. Build request options. Include the RP ID, challenge, timeout and user-verification preference. For username-less discoverable sign-in, omit or leave allowCredentials empty. For an identified account, you may provide only that account’s accepted credential IDs. Avoid exposing credential allow lists unnecessarily to unauthenticated callers.
  3. Call the browser API. Convert the request options as required by your client library, then call navigator.credentials.get({ publicKey }). Send the resulting assertion to your backend in the expected serialization format.
  4. Resolve the account from verified credential data. Verify the challenge, exact expected origin, RP ID hash, required user-presence and user-verification flags, and assertion signature using the stored public key. For a discoverable credential, the verified credential can provide a user handle; do not accept an unverified client-supplied account identity. For an identified flow, confirm the credential belongs to the account being authenticated.
  5. Create the session only after verification. Reject missing, expired, mismatched or replayed challenges and any failed verification. Consume the challenge on success so it cannot be reused.

The credential ID is a lookup value, not proof of identity by itself. The signature and ceremony checks establish that the assertion corresponds to the stored credential and the expected relying party.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle origins, RP IDs and framework configuration

Configure the RP ID and allowed origin explicitly and keep them stable. The RP ID scopes credentials; a change can prevent credentials created for the previous identity from working. Validate host headers anywhere they could influence RP identity. Microsoft’s ASP.NET Core guidance specifically warns that deriving RP identity from an unchecked host header can create credential-scoping risk.

Rank #4
Sale
UGREEN USB to USB C Adapter Combo 4-Pack, 10Gbps USB C Converter Space Gray
  • Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
  • Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
  • Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
  • Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
  • Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft

Framework instructions are not interchangeable. Microsoft’s cited guidance covers ASP.NET Core Identity for .NET 10 or later and includes ServerDomain, user-verification and resident-key configuration. Use those APIs only in the documented framework and version context; for another stack, follow that stack’s current maintained library documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build account recovery and credential management

Passkey rollout is incomplete unless users and support staff can handle lost devices, compromised credentials and account changes. Provide a way to add another credential while authenticated, inspect registered credentials and revoke one. Protect credential enrollment and removal against session theft and social engineering at a level appropriate to the account.

  • Offer an account recovery route that does not silently bypass the security level of the account. Recovery codes or email flows are possible design choices, not universal requirements; assess their risks for your application.
  • Encourage users to register a backup credential when appropriate, and make it clear how to remove a credential they no longer control.
  • For higher-risk accounts, consider monitoring backup status and requiring additional verification before sensitive recovery or credential changes.
  • Revoke credentials promptly when an account is compromised, and invalidate active sessions when your incident policy requires it.

Test the full lifecycle before release

Test more than the successful sign-in on one development device. Cover the cases that exercise account binding, discovery, policy and failure handling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anker USB C Hub, 5-in-1 USBC to HDMI Splitter with 4K Display
  • 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
  • Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
  • Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
  • HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
  • What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
  • Register a passkey on a signed-in account, then authenticate with it on the same and another supported device.
  • Test both username-first and username-less paths if your product offers both, including a user who has no discoverable credential.
  • Confirm that expired or mismatched challenges, incorrect origins, RP ID mismatches, invalid signatures and missing required flags are rejected without creating a session.
  • Test duplicate enrollment, a user cancelling the authenticator prompt, unavailable credentials, revoked credentials and recovery.
  • Verify that account identifiers are not embedded in user handles, and that logs do not expose unnecessary credential data.

Browser support, native APIs and framework behavior can change. Check the current documentation for the exact platforms and library versions you intend to ship against.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server, not a passkey implementation library. It can capture an application page for documentation or UI review; it does not create or verify WebAuthn credentials. For a single screenshot request, adapt the target URL to a page you are authorized to capture:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. Before the capture, it accepts the cookie or consent banner like a visitor and removes 60+ known consent platforms, newsletter popups and chat widgets; each step can be turned off. Bot checks, blank pages and failed loads are never billed, and response headers report the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info and capture_pdf for AI agents. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo free.

Frequently Asked Questions

Does implementing passkeys mean I have to remove passwords?

No. WebAuthn defines the credential ceremonies; your application chooses whether to offer passkeys alongside passwords or make them the primary route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a passkey send a fingerprint or face scan to my server?

No. User verification happens locally at the authenticator or platform; biometric data is not revealed to the relying party.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.