The private key stays on the authenticator. Authdog stores the public credential and verifies the WebAuthn ceremony. Enable the method per environment.
Enable passkeys
In the Authdog console:
- Select the project and environment.
- Open Authentication > Methods.
- Enable Passkeys.
No vendor credentials are required. The relying-party ID is the identity host for that environment, including a custom domain when one is in use. A passkey registered on one host does not sign in on another.
Keep another sign-in method enabled. A user who loses every authenticator needs a path back in.
Register and sign in
Registration requires an authenticated session. A user signs in with another method first, then adds a passkey from the account session. Authentication uses a discoverable credential and local user verification.
Authdog accepts ES256 and RS256 keys and requests no attestation, so the ceremony does not collect device-identifying attestation.
Test it
- In development, sign in with email or a social provider.
- Register a passkey from the authenticated account session. Try a platform authenticator and, if you support them, a security key.
- Sign out and sign in with the passkey.
- Cancel the prompt once and confirm the user can fall back to the other method.
- Repeat in production on the production identity host. A passkey created against the development host will not work there.
Related
| Read | To learn how to |
|---|---|
| Passkeys | Registration, verification, and recovery |
| Authentication | Methods on the same screen |
| Marketplace | The listing for this integration |