WebAuthn
Public-key authentication standard
Web Authentication (WebAuthn) is a web standard published by the World Wide Web Consortium (W3C). It defines an API that websites use to authenticate with WebAuthn credentials (commonly known as passkeys) and outlines what WebAuthn authenticators should do.
Nº Q55637499 ★★★
Rare · Literature
WebAuthn
Public-key authentication standard
Web Authentication (WebAuthn) is a web standard published by the World Wide Web Consortium (W3C). It defines an API that websites use to authenticate with WebAuthn credentials (commonly known as passkeys) and outlines what WebAuthn authenticators should do.
Last price
—
Floor price
—
7-day median
—
30-day sales
0
30-day range
—
In circulation
0
Price history
median
low – high
sales
No sales in this period
Show table
| Date | median | Low | High | sales |
|---|
Sales history
- Last sale
- —
- 30-day average
- —
- 30-day low
- —
- 30-day high
- —
- Sales 7d
- 0
- Sales 30d
- 0
No sales yet.
Anonymous sales: no buyer or seller shown. Figures count player-to-player sales only.
From Wikipedia
Web Authentication (WebAuthn) is a web standard published by the World Wide Web Consortium (W3C). It defines an API that websites use to authenticate with WebAuthn credentials (commonly known as passkeys) and outlines what WebAuthn authenticators should do. It solves many of the issues of traditional password-based authentication by verifying the user's identity with digital signatures. Although WebAuthn is often touted as a complete replacement for passwords, most websites that implement it continue to use passwords in some capacity. To use WebAuthn, users require a compatible authenticator. The standard does not specify how to store the keys required for signing, so a variety of authenticator types can be used. The most common authenticator type is a platform authenticator, which is built into the operating system of the device. Common platform authenticators include Android, Apple Keychain and Windows Hello. These make use of hardware security features (such as TEE and TPM), and often sync credentials between devices for ease-of-use. Another common authenticator type is a roaming authenticator, where a separate hardware device authenticates the user by connecting over USB, Bluetooth Low Energy, or near-field communications (NFC). Most smartphones can be used as roaming authenticators, and dedicated physical security keys are also used. WebAuthn is effectively backward compatible with FIDO Universal 2nd Factor (U2F) as they both use the CTAP protocol. Password managers can also be used as an authenticator, often with cloud sync. Where credentials sync is not viable or possible, WebAuthn Hybrid Transport can be used to access credentials stored on another authenticator such as a smartphone. Like legacy U2F, WebAuthn is resistant to some phishing attacks as the authenticator only offers credentials that were registered on the same website. However, unlike U2F, WebAuthn can be implemented in a passwordless manner. Moreover, a roaming hardware authenticator resists malware, since the...
Text: Wikipédia, CC BY-SA 4.0. · Image: Trscavo (CC BY-SA 4.0) ·
Related cards
SAML
XML-based format and protocol for exchanging authentication and authorization data between parties
Nº Q1758048 ★★
OAuth
Open standard for access delegation, commonly used as a way for internet users to grant websites or applications access to their information on other websites but without giving them the passwords
Nº Q743238 ★★★
JSON Web Token
JSON-based open standard (RFC 7519) for passing claims between parties in web application environment
Nº Q22284678 ★★★
WebRTC
API definition drafted by W3C that supports browser-to-browser communication without plugins
Nº Q1089715 ★★★
FIDO Alliance
Industry consortium working on authentication mechanisms, including the UDF protocol for two-factor authentication
Nº Q15731702 ★★
YubiKey
Product line of hardware authentication devices for multi-factor authentication
Nº Q19600525 ★★★