WebAuthn / passkeys support
Published Updated
WebAuthn (PublicKeyCredential) lets a web app request creation of, and later
request an assertion from, a public-key credential bound to an authenticator — built
into the device or an external security key — instead of a password; the relying
party’s server verifies the result. Per MDN, a passkey is a discoverable WebAuthn
credential built on this same API.
Browser & ecosystem support
Section titled “Browser & ecosystem support”- Legend
- Yes
- Partial
- Flag
- No
- Unknown
| Browser / Platform | Support | Versions | Confidence | Source | Notes |
|---|---|---|---|---|---|
| Chrome (Desktop) | Yes | 67 | high | source | — |
| Chrome (Android) | Yes | 70 | high | source | — |
| Edge (Desktop) | Yes | 18 | high | source | — |
| Firefox (Desktop) | Yes | 60 | high | source | 1 |
| Firefox (Android) | Partial | 60 → 92 | high | source | 2 |
| Safari (macOS) | Yes | 13 | high | source | — |
| Safari (iOS) | Yes | 13 | high | source | 3 |
| Samsung Internet | Yes | 10.0 | high | source | 4 |
| WebView (Android) | Yes | 70 | high | source | 5 |
- Only supports USB U2F tokens.
- Only supports USB U2F tokens.
- Derived by browser-compat-data mirroring from Safari.
- Derived by browser-compat-data mirroring from Chrome Android.
- Derived by browser-compat-data mirroring from Chrome Android.
How to use it
Section titled “How to use it”Register a credential from the page once your server has issued a challenge:
async function registerCredential(challenge, userId) { return navigator.credentials.create({ publicKey: { challenge, rp: { name: 'Example App' }, user: { id: userId, name: 'user@example.com', displayName: 'Example User' }, pubKeyCredParams: [{ type: 'public-key', alg: -7 }], authenticatorSelection: { residentKey: 'required' }, }, });}How to detect it at runtime
Section titled “How to detect it at runtime”Feature-detect PublicKeyCredential before offering a WebAuthn or passkey sign-in path:
function supportsWebAuthn() { return 'PublicKeyCredential' in window;}
async function startSignIn() { if (!supportsWebAuthn()) { return signInWithPassword(); } return navigator.credentials.get({ publicKey: buildRequestOptions() });}Practical checklist
Section titled “Practical checklist”- Feature-detect
window.PublicKeyCredentialbefore showing any WebAuthn or passkey UI. - Per MDN, a passkey is a discoverable WebAuthn credential — it uses the same
navigator.credentialsAPI as classic WebAuthn, not a separate one. - This table reflects baseline
PublicKeyCredentialsupport; verify passkey-specific behavior (such as autofill) for your target platforms directly rather than assuming it from these version numbers alone. - Always keep a fallback sign-in path (e.g. password or email link) for visitors on a
browser or device that doesn’t support
PublicKeyCredential.
Where to go next
Section titled “Where to go next”- WebAuthn and passkeys — the full registration/authentication ceremony and server-side responsibilities
- Persistent storage — another browser capability compatibility page
← Back to the Compatibility explorer.