implementing-hardware-security-key-authentication - Implement FIDO2 hardware security key authentication
Build WebAuthn relying party authentication with hardware keys, YubiKey enrollment, discoverable credentials, and passkey migration workflows.
Tags
Updated: 2026-10-04Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Configure WebAuthn relying party servers
- Implement credential registration ceremonies
- Implement credential authentication ceremonies
- Enroll and manage YubiKeys
- Support discoverable credential flows
- Plan passkey migration strategies
- Verify authenticator attestations
- Manage credential lifecycle events
Inputs
- Relying party identity
- User account data
- Registered credential records
- Authenticator configuration
- Attestation preferences
- User verification policy
- Passkey migration policy
- Recovery policy
Outputs
- WebAuthn relying party server
- Registered credential records
- Authentication results
- Credential lifecycle state
- YubiKey enrollment records
- Security event flags
- Passkey migration workflows
Requirements
- Python 3.10 or later
- python-fido2 2.0.0 or later
- Flask
- cryptography
- HTTPS-enabled web server
- FIDO2-compatible authenticator
- WebAuthn-compatible browser
- Public-key cryptography knowledge
- HTTP session management knowledge
