Implementing Passkeys Using Keycloak
nutfieldsecurity.com
nutfieldsecurity.com
In one step, Passkeys provide multiple forms of authentication including:
* FIDO2 based credential * Origin verification of the requesting web app by the Platform Authenticator (this part makes them phish resistant) * user password, because you had to unlock the platform authenticator in the first place * device authentication, because the passkeys are stored within device bound platform authenticators
Don't let your lazy compliance people tell you passkeys aren't MFA.