16-part series
Beyond the core ceremony, WebAuthn has a growing set of extensions and adjacent APIs that solve specific production problems - PRF for end-to-end encryption, credProtect for security keys, Related Origins for multi-domain brands, the Signal API for keeping credential lists in sync, and credential exchange for moving passkeys between providers. This series covers what each one does, its browser support, and when it is worth adopting.
Each article stands on its own - start wherever your problem is.
Explore Credential Manager Trust Group Keys (CMTG), the WebAuthn extension enhancing passkeys through verifiable device relationships & anti-phishing protection.
Learn how FedCM replaces third-party cookies with browser-mediated federated login, what browsers support it and how it fits alongside passkeys.
Explore challenges and solutions for handling non-resident keys in WebAuthn / passkey systems and Conditional UI (passkey autofill).
Discover how to create & login with passkeys in cross-origin iframes with our guide. Learn about iframes in WebAuthn, security policies & implementation.
WebAuthn PRF extension explained. Play with the Passkey PRF Demo, see OS & browser support status and learn how PRF enables end-to-end encryption
Understand the role of Web Bluetooth API for passkeys! Learn how Bluetooth availability detection enhances Cross-Device Authentication (CDA) with WebAuthn.
Discover WebAuthn Level 3 client capabilities via getClientCapabilities() to improve passkey integration, enhance UX &streamline authentication flows.
This article explains how Conditional UI for sign-up processes could look like. In particular, the new WebAuthn Conditional Registration Explainer is discussed.
Enable secure passkey migration with CXP & CXF - the new FIDO standards for seamless cross-platform import and export of credentials.
How the credProtect extension affects security key interoperability across Chrome, Safari and Firefox - and what relying parties can do.
Explore the CDA-first approach for seamless WebAuthn cross-device authentication with passkeys stored on smartphones as a mobile-first strategy.
A deep dive into WebAuthn immediate mediation. Learn how it creates a single sign-in button, avoids confusing QR codes & builds a smarter login flow.
Discover WebAuthn's use of asymetric encryption algorithms and pubKeyCredParams in passkey auth and the role of credentialPublicKey, CBOR and COSE.
Learn about WebAuthn Public Key Credential Hints / User-Agent Hints, their availability, how they can be used and what limitations and recommendations exist.
Learn how WebAuthn Related Origin Requests (ROR) enable passkeys across multiple domains. Complete implementation guide with real-world examples.
Learn how the WebAuthn Signal API enables seamless passkey deletion and metadata updates (user.name, user.displayName) on client-side authenticators.
See every login journey clearly, diagnose failures faster and keep your existing IDP in place.