Skip to content

WebAuthn / passkeys support

Published Updated

WebAuthn (PublicKeyCredential) lets a web app request creation of, and later request an assertion from, a public-key credential bound to an authenticator — built into the device or an external security key — instead of a password; the relying party’s server verifies the result. Per MDN, a passkey is a discoverable WebAuthn credential built on this same API.

  • Legend
  • Yes
  • Partial
  • Flag
  • No
  • Unknown
Browser / PlatformSupportVersionsConfidenceSourceNotes
Chrome (Desktop)Yes67highsource—
Chrome (Android)Yes70highsource—
Edge (Desktop)Yes18highsource—
Firefox (Desktop)Yes60highsource1
Firefox (Android)Partial60 → 92highsource2
Safari (macOS)Yes13highsource—
Safari (iOS)Yes13highsource3
Samsung InternetYes10.0highsource4
WebView (Android)Yes70highsource5
  1. Only supports USB U2F tokens.
  2. Only supports USB U2F tokens.
  3. Derived by browser-compat-data mirroring from Safari.
  4. Derived by browser-compat-data mirroring from Chrome Android.
  5. Derived by browser-compat-data mirroring from Chrome Android.

Source data: /compatibility/webauthn.json · Global usage: 92 % (StatCounter 2026-05)

Source: spec · MDN · Last verified 2026-10-03 · Confidence: high (computed from sources)

Register a credential from the page once your server has issued a challenge:

async function registerCredential(challenge, userId) {
return navigator.credentials.create({
publicKey: {
challenge,
rp: { name: 'Example App' },
user: { id: userId, name: 'user@example.com', displayName: 'Example User' },
pubKeyCredParams: [{ type: 'public-key', alg: -7 }],
authenticatorSelection: { residentKey: 'required' },
},
});
}

Feature-detect PublicKeyCredential before offering a WebAuthn or passkey sign-in path:

function supportsWebAuthn() {
return 'PublicKeyCredential' in window;
}
async function startSignIn() {
if (!supportsWebAuthn()) {
return signInWithPassword();
}
return navigator.credentials.get({ publicKey: buildRequestOptions() });
}
  • Feature-detect window.PublicKeyCredential before showing any WebAuthn or passkey UI.
  • Per MDN, a passkey is a discoverable WebAuthn credential — it uses the same navigator.credentials API as classic WebAuthn, not a separate one.
  • This table reflects baseline PublicKeyCredential support; verify passkey-specific behavior (such as autofill) for your target platforms directly rather than assuming it from these version numbers alone.
  • Always keep a fallback sign-in path (e.g. password or email link) for visitors on a browser or device that doesn’t support PublicKeyCredential.

← Back to the Compatibility explorer.