implementing-hardware-security-key-authentication - Implement FIDO2 hardware security key authentication
Builds FIDO2/WebAuthn registration and authentication flows, YubiKey enrollment, discoverable credentials, and passkey migration using python-fido2.
Tags
Updated: 2026-10-04Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Configure relying party servers
- Implement credential registration
- Implement assertion authentication
- Manage YubiKey enrollment
- Support discoverable credentials
- Migrate passwords to passkeys
- Detect cloned credentials
- Manage credential lifecycles
Inputs
- Relying party identity
- User account data
- Registered credential records
- WebAuthn client responses
- YubiKey enrollment data
- Passkey migration policy
Outputs
- Credential records
- Authentication results
- Updated signature counters
- Credential security events
- Key lifecycle records
- Passkey migration status
Requirements
- Python 3.10 or later
- python-fido2 2.0.0 or later
- Flask and cryptography libraries
- HTTPS-enabled web server
- FIDO2-compatible authenticator
- WebAuthn-capable modern browser
