Get your free and exclusive 80-page Banking Passkey Report

Can passkeys be used on other domains without an iframe?

Vincent Delitz

Vincent

Created: April 7, 2025

Updated: June 16, 2025

iframe passkeys webauthn cover

Read the full article

Discover how to create & login with passkeys in cross-origin iframes with our guide. Learn about iframes in WebAuthn, security policies, & implementation.

Read the full article

Read by 5,000+ security leaders.


Can passkeys bound to one domain be used on another domain without an iframe, and what’s the current browser stance?#

Currently, passkeys created for one domain (bound to a specific Relying Party ID) cannot be directly used on another domain without an iframe. This restriction is central to passkeys' strong phishing-resistant security model, as passkeys are strictly associated with their original creation domain.

Why Domain Binding Exists:#

  • Domain binding ensures that passkeys cannot be misused on malicious or unrelated sites, significantly reducing phishing attacks.
  • The Relying Party ID (domain) is a fundamental security measure within the WebAuthn standard.
passkeys cross domain usage without iframe

Current Browser Stance:#

  • All major browsers - Chrome, Firefox and Safari - currently enforce strict domain-binding rules.
  • Passkeys must be used within their original domain context or explicitly allowed via secure, embedded iframe integrations.
  • A new concept called "Related Origins" is emerging, allowing closely related domains (like subdomains or trusted partner domains) to access passkeys without needing an iframe.
  • However, as of now, no browsers officially support "Related Origins." There is also no specific timeline set by browser vendors for this capability.
WhitepaperEnterprise Icon

60-page Enterprise Passkey Whitepaper:
Learn how leaders get +80% passkey adoption. Trusted by Rakuten, Klarna & Oracle

Get free Whitepaper

Practical Implication:#

To use passkeys across domains today, developers must embed an iframe originating from the passkey's domain into other domains. This setup maintains security integrity while enabling cross-domain authentication flows.

In summary, passkeys remain strictly bound to their creation domain unless explicitly shared via cross-origin iframe implementations. New concepts like "Related Origins" may ease restrictions, but browser support is currently limited.

Read the full article#

iframe passkeys webauthn cover

Read the full article

Discover how to create & login with passkeys in cross-origin iframes with our guide. Learn about iframes in WebAuthn, security policies, & implementation.

Read the full article

Read by 5,000+ security leaders.

Schedule a call to get your free enterprise passkey assessment.

Talk to a Passkey Expert

Enjoyed this read?

🤝 Join our Passkeys Community

Share passkeys implementation tips and get support to free the world from passwords.

🚀 Subscribe to Substack

Get the latest news, strategies, and insights about passkeys sent straight to your inbox.

Share this article


LinkedInTwitterFacebook

Related FAQs

Related Terms

Related Articles

No articles found