Prototypes KeyholeP5 · Passkey sign-in

Sign in with a passkey, and open a note with it

Make a passkey, sign in with it, and see every check a server makes. With the PRF extension the passkey also gives a secret that encrypts a note, so the note opens only after you sign in.

1. Make a passkey

Shown by the password manager or the phone when you sign in.

No passkey yet

2. Sign in

Signed out

3. A note only the passkey opens

Sign in first. The note is encrypted with a key that comes from the passkey, and it is stored in this browser only as ciphertext.

Locked

What the server checks

Sign in to see each check.

The authenticator that holds the passkey

PartValue
StateMake a passkey to see it
How Keyhole is built
  1. Making a passkey gives the page a public key and an id. The private key stays in the phone, the laptop or the password manager.
  2. Signing in, the authenticator signs a random challenge together with the address of the page. The page checks the signature with the public key, the challenge, the address, and that you were present and verified.
  3. PRF asks the passkey for a secret made from a fixed salt. The same passkey always gives the same secret, and no other passkey can. HKDF turns it into an AES-GCM key for the note.
  4. A real product makes these checks on its server. Here they run in the browser, so every step can be seen.