Opaque, Interoperable Passkey Records (and a Go API)
Read OriginalThis article discusses the importance of passkeys for phishing resistance and proposes a standardized, opaque passkey record format (c2sp.org/passkey-record) to simplify server-side storage and interoperability. It compares existing approaches from Google and Adam Langley, introduces a PHC string-based encoding with authenticator data, and describes how applications can treat passkey records like password hashes. The article also covers transport parameters and metadata fields, aiming to make passkey library switching and database portability easier for developers.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
No top articles yet