Filippo Valsorda 7/20/2026

Opaque, Interoperable Passkey Records (and a Go API)

Read Original

This article discusses the importance of passkeys for phishing resistance and proposes a standardized, opaque passkey record format (c2sp.org/passkey-record) to simplify server-side storage and interoperability. It compares existing approaches from Google and Adam Langley, introduces a PHC string-based encoding with authenticator data, and describes how applications can treat passkey records like password hashes. The article also covers transport parameters and metadata fields, aiming to make passkey library switching and database portability easier for developers.

Opaque, Interoperable Passkey Records (and a Go API)

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet