Web Authentication: An API for accessing Public Key Credentials Level 3 is now a W3C Recommendation

Author(s) and publish date

Published:

The Web Authentication Working Group is pleased to publish Web Authentication: An API for accessing Public Key Credentials Level 3 as a W3C Recommendation.

This specification defines an API enabling the creation and use of strong, attested, scoped, public key-based credentials by web applications, for the purpose of strongly authenticating users. Conceptually, one or more public key credentials, each scoped to a given WebAuthn Relying Party, are created by and bound to authenticators as requested by the web application. The user agent mediates access to authenticators and their public key credentials in order to preserve user privacy. Authenticators are responsible for ensuring that no operation is performed without user consent. Authenticators provide cryptographic proof of their properties to Relying Parties via attestation. This specification also describes the functional model for WebAuthn conformant authenticators, including their signature and attestation functionality. 

Level 3 is the successor to Web Authentication Level 2. New features will be developed in Level 4.

Related RSS feed