WebAuthn · browser playground
Meet the
passkey ceremony.
Create a real passkey with the browser's WebAuthn API, authenticate with it, and inspect the data the browser hands back. Nothing is uploaded to a server and no private key leaves the authenticator.
Environment
WebAuthn unavailable
RP ID localhost
Step 01 · register
Use a platform authenticator, security key, or another passkey-capable authenticator. Your browser may ask for a PIN, biometric, or device approval.
Step 02 · authenticate
The demo generates a fresh challenge for every sign-in and checks that the returned client data is bound to that challenge.
Latest ceremony
Nothing captured yet
Start a ceremony above. The panel will keep the response artifacts visible so you can see the distinction between the challenge, client data, authenticator data and signature.
Passkeys are scoped to this site's relying-party ID. Clearing the local record does not remove a credential from your device; it only forgets the metadata this demo keeps in this browser.