Passkey / WebAuthn Playground
Create a real passkey and run an authentication ceremony — entirely client-side, no relying-party server involved
navigator.credentials.create() / get() directly against your device's authenticator (Touch ID, Windows Hello, a security key, or your phone) and decodes exactly what comes back. It's a sandbox for seeing the real WebAuthn ceremony and response shape — not a substitute for testing against your actual relying-party server.0 for most platform authenticators (Touch ID, Windows Hello, synced passkeys) — a real relying-party server uses it only to detect cloned hardware keys, not synced passkeys. Backup eligible / backed up tell you whether this credential is a synced passkey (eligible for cloud backup) versus a device-bound one.About this tool
The ToolNinja Passkey / WebAuthn Playground runs real WebAuthn ceremonies — navigator.credentials.create() to register a passkey, navigator.credentials.get() to authenticate with it — directly against your device's authenticator (Touch ID, Windows Hello, a hardware security key, or a synced passkey on your phone), entirely in your browser. There's no backend here, which is the point: this is a sandbox for seeing exactly what a WebAuthn ceremony produces — the credential ID, attestation/assertion response, and decoded authenticatorData flags (user present, user verified, backup eligible, backup state, sign count, AAGUID) — without having to stand up a relying-party server first. It's useful for learning how WebAuthn actually works, or as a quick sanity check that your authenticator and browser support the flow before you wire up real server-side verification. WebAuthn requires a secure context (HTTPS or localhost) and browser support for the Credential Management API — both are detected automatically, with a clear message if either is missing.
When to use it
- →Learning what a WebAuthn registration and authentication ceremony actually returns, before implementing server-side verification
- →Checking whether your current browser and authenticator (Touch ID, Windows Hello, a YubiKey) support passkeys at all
- →Seeing the difference between a synced passkey (backup eligible) and a device-bound credential (hardware key) via the decoded flags
- →Demonstrating passkeys to a team or in a presentation without needing a live backend
Tips
- ◆Sign count stays at 0 for most platform authenticators (Touch ID, Windows Hello, synced passkeys) — only hardware security keys reliably increment it, since it exists specifically to help a server detect a cloned hardware key.
- ◆"Backup eligible" means the credential can sync across a user's devices via a password manager or OS keychain — that's what makes something a true passkey rather than a device-bound credential.
- ◆If the authenticator prompt doesn't appear, check that you're on HTTPS or localhost — WebAuthn refuses to run in an insecure context.
Frequently asked questions
Does this tool verify my passkey against a real server?
No — there's no backend involved at all. It calls the browser's WebAuthn API directly and decodes the response locally. Real passkey verification requires a relying-party server that stores the public key from registration and checks the signature on every subsequent authentication; this tool only shows you what the browser-side ceremony produces.
Why does my authenticator prompt not appear?
The two most common causes: you're not in a secure context (WebAuthn requires HTTPS or localhost — this is enforced by the browser, not this tool), or your browser/OS combination doesn't support platform authenticators. Check the warning banner at the top of the tool, which detects both conditions.
What's the difference between a passkey and a traditional WebAuthn security key?
Both use the same underlying WebAuthn protocol. A traditional security key (like a YubiKey) is device-bound — the private key never leaves that one physical device. A passkey is typically synced — the private key is backed up (usually encrypted) to a password manager or OS keychain and available across your devices. The 'backup eligible' flag this tool decodes tells you which kind you just created.