The article proposes a standardized, interoperable encoding format for WebAuthn passkey records, drawing syntax from PHC strings to simplify server-side storage and management. This specification aims to reduce fragmentation across different database schemas recommended by various providers while maintaining the security benefits of passkeys. It also introduces a Go API to facilitate implementation.
Background
Passkeys are gaining traction as a phishing-resistant alternative to passwords, but inconsistent server-side implementation standards have created integration challenges. This proposal seeks to establish a common string format for storing passkey credentials, similar to how password hashes are currently handled.
- Source
- Lobsters
- Published
- Jul 21, 2026 at 06:46 AM
- Score
- 7.0 / 10