implementing-hardware-security-key-authentication - Implement FIDO2 and WebAuthn security key authentication
Builds a Python FIDO2/WebAuthn relying party server for registration, authentication, YubiKey enrollment, passkeys, and user verification policies.
Tags
Updated: 2026-10-04Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Configure relying party identity
- Implement credential registration ceremonies
- Implement authentication ceremonies
- Enroll primary and backup YubiKeys
- Manage credential lifecycle
- Plan passkey migration
Inputs
- Relying party domain
- User account data
- Credential records
- Authenticator responses
- Attestation preferences
- User verification policy
Outputs
- Registered credential records
- Authenticated user sessions
- Credential lifecycle changes
- YubiKey enrollment records
- Clone detection security events
- Passkey migration flows
Requirements
- Python 3.10 or later
- python-fido2 2.0.0 or later
- Flask and cryptography libraries
- HTTPS-enabled web server
- FIDO2-compatible authenticator
- WebAuthn-capable modern browser
- Public key cryptography knowledge
- HTTP session management knowledge
