WebAuthn (Web Authentication) is a W3C and FIDO Alliance standard that enables web applications to authenticate users using public-key cryptography rather than passwords, through hardware or software authenticators such as security keys, platform biometrics, and passkeys. The browser exposes the navigator.credentials API, which delegates cryptographic operations to a CTAP-compliant authenticator; the authenticator generates a key pair, stores the private key in a secure enclave, and signs authentication challenges that the relying party verifies using the registered public key. WebAuthn eliminates shared secrets from the authentication path, making phishing, credential stuffing, and replay attacks fundamentally impossible by design. It is the technical foundation of the passkey ecosystem deployed by Apple, Google, and Microsoft.
Content
- WebAuthn emerged from the FIDO Alliance’s U2F (Universal 2nd Factor) and UAF (Universal Authentication Framework) standards of 2014, which demonstrated hardware-bound phishing-resistant authentication at scale. These were unified and elevated to a W3C recommendation in March 2019, with Level 2 published in April 2021. The passkey concept — synchronised WebAuthn credentials stored in platform credential managers — was jointly announced by Apple, Google, and Microsoft in May 2022, dramatically lowering the friction barrier for adoption.
- The protocol operates through a registration and authentication flow. During registration, the browser calls navigator.credentials.create() with a challenge from the relying party; the authenticator generates a new asymmetric key pair, stores the private key in a tamper-resistant enclave, and returns the public key and an attestation statement. During authentication, the browser calls navigator.credentials.get() with a new server challenge; the authenticator signs the challenge-plus-origin data with the private key; the server verifies the signature against the stored public key.
- A critical security property is the origin binding: the key pair is scoped to the specific domain (relying party ID), making it impossible to use a credential registered at a legitimate domain to authenticate on a phishing site, even if the user is deceived. Biometric verification — Touch ID, Face ID, Windows Hello — acts as a user-presence signal enforced by the authenticator, not transmitted to the server, preserving privacy.
- In 2024-2025, passkeys have crossed the mainstream adoption threshold with over a billion accounts supporting them across major platforms. Conditional UI enables browsers to autofill passkeys in traditional login forms, smoothing the migration from passwords. Enterprise deployments are exploring enterprise attestation for binding passkeys to managed devices, and the FIDO Alliance is standardising cross-device credential provisioning to handle device loss scenarios. WebAuthn is increasingly referenced in authentication standards for decentralised identity systems including W3C DID and verifiable credential presentations.