A passkey is an account credential whose private key stays with an authenticator while the server stores a public key. Registration and sign-in each require a fresh server challenge, origin and relying-party scope checks, and a verified response before a session is created. The browser UI may be smooth, but server mistakes can still bind a credential to the wrong account or accept a replay. This track follows a case-review product with shared devices, synced passkeys, and account recovery needs. It treats authenticator choice and credential removal as product states, not as hidden browser details.
Topics in this track
- Passkey Registration Challenge and Credential Binding — Issue a fresh server challenge and bind the returned public key to the intended signed-in account.
- Passkey Assertion, Origin, and Signature Verification — Verify an assertion against a stored public key and a one-use sign-in challenge before creating a session.
- Passkey Conditional Sign-In and Fallback — Offer passkeys without trapping users whose browser, authenticator, or credential is unavailable.
- Passkey Management, Recovery, and Step-Up — Let users remove lost credentials and require fresh assurance for sensitive account changes.
Prerequisite paths
Identity and Application Security; Authorization and Tenant Boundaries.
Neighbor track
Practice path
Build Project: passkey account lifecycle and check decisions in Web Development: passkey and checkout decisions quiz.
