MrWho

WebAuthn and Passkeys Guide

Last updated: 2026-03-29

MrWhoOidc supports WebAuthn-based authentication for passkeys and security keys.

What WebAuthn Is Used For

WebAuthn can be used to:

Operational Requirements

Before enabling WebAuthn, verify:

Deployment Notes

WebAuthn is sensitive to origin and RP ID mismatches.

Practical guidance:

User Experience Guidance

For public deployments, describe WebAuthn in plain language:

Plan for:

Administrative Guidance

Administrators should treat WebAuthn as a security feature rollout, not just a toggle.

Recommended steps:

  1. enable it in a non-production environment first
  2. validate browser/device coverage for your user base
  3. define recovery and support workflows
  4. communicate the user-facing terminology before rollout

Security Notes