WebAuthn
A W3C standard that enables passwordless authentication in web browsers using public-key cryptography, forming the basis of passkeys and FIDO2.
WebAuthn (Web Authentication) is a W3C standard that enables passwordless authentication in web browsers. It uses public-key cryptography: a unique key pair is generated for each website, with the private key stored securely on the user’s device (in a hardware security module) and the public key registered with the website.
During authentication, the browser asks the user to verify their identity locally (via biometrics, PIN, or security key) and then signs a challenge from the server with the private key. The server verifies the signature against the stored public key.
WebAuthn is phishing-resistant by design, the credential is cryptographically bound to the domain, so it cannot be used on a fake site. It’s the foundation of passkeys and FIDO2 authentication.
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide