Glossary

WEBAUTHN & PASSKEYS
defined.

A W3C standard for phishing-resistant authentication using public-key cryptography and hardware-backed credentials.

A–Z

What is WebAuthn & Passkeys?

WebAuthn (and its consumer-friendly cousin, passkeys) replaces passwords and OTP-based MFA. Credentials are bound to the relying party origin, so phishing sites cannot use them. Passkeys can sync via iCloud Keychain or Google Password Manager for cross-device portability.

Where this shows up.

See our web application penetration testing, API security testing, network penetration testing, and cloud security audit services for how we test for and defend against this class of issue.

Test for this in your stack

BOOK A FREE
scoping call.

30-minute call with an OSCP-certified engineer. Tailored proposal in 24 hours.