Flow 02 · Authenticator
A passkey is a key for one origin.
You store a public key. Later, the authenticator signs a challenge you just made up. A lookalike site can’t get that signature, because the key is bound to your origin and the lookalike isn’t it.
Watch for
- Your server makes the challenge, once. The browser echoes it back inside
clientDataJSON. - The fingerprint or PIN stays on the device. You get a flag that says verification happened.
- Cite WebAuthn Level 3. It’s been a Recommendation since 25 August 2026. Level 4 is still a first draft.
Failure modes
- Checking the signature and skipping the origin. The origin in the client data is the one that counts, not whatever the page says it is.
- Treating a synced passkey and a device-bound security key as the same thing. A lot of workforce apps actually want the key that can’t leave the device.
- Account recovery that still emails a one-time code. You’ve put a phishable door next to the one you just locked.