Passkey / WebAuthn Playground

Create a real passkey and run an authentication ceremony — entirely client-side, no relying-party server involved

WebAuthn requires a secure context (HTTPS or localhost). This page isn't running in one right now.
There's no backend here — this page calls navigator.credentials.create() / get() directly against your device's authenticator (Touch ID, Windows Hello, a security key, or your phone) and decodes exactly what comes back. It's a sandbox for seeing the real WebAuthn ceremony and response shape — not a substitute for testing against your actual relying-party server.
Click "Create a passkey" to start — your browser will prompt for Touch ID, Windows Hello, or a security key
Sign count increments on every authentication for a hardware security key, but stays at 0 for most platform authenticators (Touch ID, Windows Hello, synced passkeys) — a real relying-party server uses it only to detect cloned hardware keys, not synced passkeys. Backup eligible / backed up tell you whether this credential is a synced passkey (eligible for cloud backup) versus a device-bound one.

About this tool

The ToolNinja Passkey / WebAuthn Playground runs real WebAuthn ceremonies — navigator.credentials.create() to register a passkey, navigator.credentials.get() to authenticate with it — directly against your device's authenticator (Touch ID, Windows Hello, a hardware security key, or a synced passkey on your phone), entirely in your browser. There's no backend here, which is the point: this is a sandbox for seeing exactly what a WebAuthn ceremony produces — the credential ID, attestation/assertion response, and decoded authenticatorData flags (user present, user verified, backup eligible, backup state, sign count, AAGUID) — without having to stand up a relying-party server first. It's useful for learning how WebAuthn actually works, or as a quick sanity check that your authenticator and browser support the flow before you wire up real server-side verification. WebAuthn requires a secure context (HTTPS or localhost) and browser support for the Credential Management API — both are detected automatically, with a clear message if either is missing.

When to use it

  • →Learning what a WebAuthn registration and authentication ceremony actually returns, before implementing server-side verification
  • →Checking whether your current browser and authenticator (Touch ID, Windows Hello, a YubiKey) support passkeys at all
  • →Seeing the difference between a synced passkey (backup eligible) and a device-bound credential (hardware key) via the decoded flags
  • →Demonstrating passkeys to a team or in a presentation without needing a live backend

Tips

  • ◆Sign count stays at 0 for most platform authenticators (Touch ID, Windows Hello, synced passkeys) — only hardware security keys reliably increment it, since it exists specifically to help a server detect a cloned hardware key.
  • ◆"Backup eligible" means the credential can sync across a user's devices via a password manager or OS keychain — that's what makes something a true passkey rather than a device-bound credential.
  • ◆If the authenticator prompt doesn't appear, check that you're on HTTPS or localhost — WebAuthn refuses to run in an insecure context.

Frequently asked questions

Does this tool verify my passkey against a real server?

No — there's no backend involved at all. It calls the browser's WebAuthn API directly and decodes the response locally. Real passkey verification requires a relying-party server that stores the public key from registration and checks the signature on every subsequent authentication; this tool only shows you what the browser-side ceremony produces.

Why does my authenticator prompt not appear?

The two most common causes: you're not in a secure context (WebAuthn requires HTTPS or localhost — this is enforced by the browser, not this tool), or your browser/OS combination doesn't support platform authenticators. Check the warning banner at the top of the tool, which detects both conditions.

What's the difference between a passkey and a traditional WebAuthn security key?

Both use the same underlying WebAuthn protocol. A traditional security key (like a YubiKey) is device-bound — the private key never leaves that one physical device. A passkey is typically synced — the private key is backed up (usually encrypted) to a password manager or OS keychain and available across your devices. The 'backup eligible' flag this tool decodes tells you which kind you just created.

Related tools

🥷 ToolNinja