461 karma · joined January 19, 2012
I’ve spent the last 4 years working on the fido2-net-lib and been running the Passwordless api for about two years now. Happy to answer any questions.
I’ve worked on a open source library for fido2 for about 4 years and we created an API that makes it A LOT simpler to get started.
And when ever you want to leave the API/Service you can just migrate to whatever self hosted webauthn service you’ve setup.
Happy to answer any questions.
If the user is not running a model OS they could still be supported by using what is known as a security key (yubico) etc.
The Passwordless API can also help with out of band authentication (using a iOS device to sign in on unsupported old laptop)
While physical devices probably will mostly be used for enterprises and us nerds, “platform Authenticators (e.g passkeys) offer much of the same security without the physical device
Disclosure: We built an open source library and an API that makes it easy to add WebAuthn/Fido to your existing web app. It’s available at for those who want to take a look. https://www.passwordless.dev/
There is also a more configurable demo page for the library where you can turn metadata on/off (the api is default off)
It’s available at https://passwordless.dev
Note: We also maintain the open source fido2-net-lib, the API just lowers the friction for devs.
The API itself work great with yubikeys (“cross-platform”) and I use them myself.
What device are you on? Unfortunately your device seem to not support “platform”-authentication (built in, TPM based)
I test for platform support but mistakenly only hide the test button, not the text queue. Thanks for telling me.
I’ve been working on one of the leading open source servers for a couple of years and it’s nice to see the real world benefits.
If anyone is interested we run an API[0] that makes it really easy to get started with WebAuthn
(I’m also the creator and maintainer of fido2-net-lib)
Disclaimer: I maintain an open source FIDO2 library.
However WebAuthn has the might of device-, OS and browser makers behind it which improves the chances of wide adoption and “what users will expect”-rate.
For those who do not want to understand all the complexity, but still leverage high security and “fingerprint / faceid” sign in on their web app we created passwordless.dev.
It’s a very easy way to try out and implement webauthn in your project. Happy to help fokes get started if you’re interested!
You can get your API key or run the demo on:
I built it to be an example to explain APIs. Turned out to beautiful to listen to, so I keep it alive for my own amusement.
I'd like to avoid JWTs and use the simplicity of "Basic" (username/password)... but borrowing your idea I could generate it clientside on the website? Enter email and immediately display a API key (base64 of email+random secret/guid) that is stored ("activated") when the first API call hits the server.
If you try to call the API with same email but different secret, it's 401.
It's indeed going to have a free tier with throttling. A paid tier with other rate limits and some premium features might come down the road.
Is it the same problem even if you run it in backgorund? Have some listeners that will pause the youtube video when that happens (which should minimize CPU)
Creator here, if you have any feedback, please just comment here or ping me on twitter @andersaberg, I'll take airport requests etc there :)
Have a good one, A