Home Supported Standards Terms & Conditions Privacy Policy Documentation Contact About

← Return to home

WebAuthn Lab — run a real ceremony against your authenticator

This page is the relying party. Build the options, press the button, and a real authenticator — a YubiKey, a platform authenticator, whatever this browser can reach — performs a real WebAuthn ceremony. Every artifact below is genuine.

The RP ID is not a free field. WebAuthn binds a ceremony to the calling origin: the RP ID must be this page's host, or a registrable parent of it. This page cannot run a ceremony for a domain it does not own — and that refusal is the phishing resistance, not a limitation to route around. To examine a ceremony belonging to someone else's relying party, use the Analyzer (paste the artifacts) or the browser extension (watch the call as it happens).

What this browser can do
1 — Registration navigator.credentials.create()
2 — Authentication navigator.credentials.get()
Ceremony Trace
Client Data
Authenticator Data
Attestation Object
Credential Public Key (COSE_Key)