Passkey sign-in (P5)
Sign in with a passkey, see every check a server would make, and open a note with the passkey's PRF secret.
Making a passkey
The page asks the browser for a passkey that is stored on the authenticator and needs the person to be verified. It keeps the public key, the id, the authenticator's AAGUID and whether the passkey can be synced.
The eight checks
Signing in, the authenticator signs a random challenge. The page checks the signature with the stored public key, that the challenge is the one it sent, that the page address and the site id match, that it is a sign-in, that a person was present and verified, and that the counter did not go back.
The note
The PRF extension gives a secret made from a fixed salt. The same passkey always gives the same secret, and no other passkey can. HKDF turns it into an AES-GCM key, and the note is stored only as ciphertext. It opens after the next sign-in with the same passkey.
Previous: Encrypted form (P4). Next: Client portal (P6).