This section describes the status of this document at the time of its publication.
A list of current
W3C publications and the latest revision of this
technical report can be found in the
W3C technical
reports index at http://www.w3.org/TR/.
This document was published by the Web Authentication Working Group
as an Editors' Draft. This document is intended to become a W3C Recommendation.
Feedback and comments on this specification are welcome. Please use
Github issues.
Discussions may also be found in the
[email protected] archives.
Publication as an Editors' Draft does not imply endorsement by
W3C and its Members. This is a draft document and may
be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to cite
this document as other than a work in progress.
This document was produced by a group operating under the
W3C Patent Policy.
W3C maintains a
public list of any
patent disclosures made in connection with the deliverables of the group; that page also
includes instructions for disclosing a patent. An individual who has actual knowledge of a
patent that the individual believes contains
Essential
Claim(s) must disclose the information in accordance with
section 6 of the
W3C Patent Policy.
This document is governed by the 03 November 2023 W3C Process Document.
1. Introduction
This section is not normative.
This specification defines an API enabling the creation and use of strong, attested, scoped, public key-based
credentials by web applications, for the purpose of strongly authenticating users. A public key credential is
created and stored by a WebAuthn Authenticator at the behest of a WebAuthn Relying Party, subject to user consent. Subsequently, the