---
title: "WebAuthn — Identity Glossary | IDSync"
description: "WebAuthn is the W3C browser API that lets web apps authenticate users with public-key cryptography backed by hardware — the foundation underneath passkeys…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "WebAuthn",
          "item": "https://idsync.com/glossary/webauthn"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/webauthn",
      "name": "WebAuthn",
      "alternateName": [
        "Web Authentication API",
        "Web Authentication"
      ],
      "description": "WebAuthn is the W3C browser API that lets web apps authenticate users with public-key cryptography backed by hardware — the foundation underneath passkeys and security keys.",
      "url": "https://idsync.com/glossary/webauthn",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Do I need WebAuthn if I have passkeys?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes — passkeys are *implemented using* WebAuthn. You build to the WebAuthn API; the OS/browser surfaces passkeys to the user."
          }
        },
        {
          "@type": "Question",
          "name": "Browser support?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Universal in modern browsers since 2019. Safari, Chrome, Edge, Firefox all support it."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  WebAuthn 

Authentication

# WebAuthn (Web Authentication API)

WebAuthn is the W3C browser API that lets web apps authenticate users with public-key cryptography backed by hardware — the foundation underneath passkeys and security keys.

Last reviewed 3 months ago

Key points

-   W3C standard, supported in every major browser
-   Underlies passkeys (synced) and security keys (hardware-only)
-   Phishing-resistant by design (origin binding)
-   Part of the FIDO2 specification family alongside CTAP
-   Replaces passwords for both first- and second-factor scenarios

## What it is

WebAuthn is the JavaScript API browsers expose so a website can ask the operating system or a security key, _please prove who this user is using a public/private key pair you hold._ It's the protocol layer underneath both passkeys and traditional FIDO2 security keys.

## How it works

-   **Registration**: site calls `navigator.credentials.create()`. The authenticator (Touch ID, Windows Hello, YubiKey) generates a key pair scoped to that origin. The public key is sent to the server.
-   **Authentication**: site calls `navigator.credentials.get()`. The authenticator signs a server challenge with the private key. The server verifies with the stored public key.

Because the key is bound to the origin (`https://example.com`), a phishing page on `examp1e.com` cannot trick the authenticator into signing for it.

## When buyers care

-   Implementing passwordless or strong second-factor auth
-   Meeting CISA / NIST guidance for phishing-resistant MFA
-   Anyone building B2B SaaS, fintech, healthcare, or government-facing apps in 2026

## Common misconceptions

-   **WebAuthn ≠ passkeys.** Passkeys are _credentials_ created via WebAuthn that are typically synced via iCloud, Google Password Manager, etc. WebAuthn is the protocol; passkeys are one consumer.
-   **WebAuthn is not just for login.** It's also strong for step-up auth on sensitive actions.

## FAQ

### Do I need WebAuthn if I have passkeys?

Yes — passkeys are _implemented using_ WebAuthn. You build to the WebAuthn API; the OS/browser surfaces passkeys to the user.

### Browser support?

Universal in modern browsers since 2019. Safari, Chrome, Edge, Firefox all support it.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[sso](/directory/category/sso)[mfa](/directory/category/mfa)

### Vendors to evaluate

[okta](/directory/okta)[auth0](/directory/auth0)[microsoft entra](/directory/microsoft-entra)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the sso category.

[Explore tools](/directory/category/sso)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.