Skip to main content

Passkeys (WebAuthn)

Passkeys use the WebAuthn standard for phishing-resistant, passwordless authentication. Users sign in with a fingerprint, Face ID, or hardware security key. No passwords to forget or leak.

How It Works

Steward’s passkey flow is smart: it tries login first, and if the user doesn’t have a passkey registered, automatically falls back to registration.
The entire flow is a single SDK call.

SDK Usage

Passkeys require a browser environment with WebAuthn support. Calling signInWithPasskey in Node.js throws an error. Use signInWithEmail or signInWithSIWE for server-side auth.

React Usage

The <StewardLogin> component includes passkey support by default:

Peer Dependency

The SDK dynamically imports @simplewebauthn/browser for the WebAuthn ceremony. Install it as a peer dependency:
If the package is missing, signInWithPasskey throws a clear error message.

Server Configuration

To enable passkeys on your self-hosted Steward instance, set these environment variables:
PASSKEY_RP_ID must match the domain where your app is served. For local development, use localhost and set PASSKEY_ORIGIN=http://localhost:3000.

API Endpoints

Login and registration endpoints accept { email, tenantId? } in the request body. MFA endpoints require the current bearer session; the options response includes challengeId, and completion sends { challengeId, response }.

Browser Support

Passkeys are supported in all modern browsers:
  • Chrome 67+
  • Safari 14+
  • Firefox 60+
  • Edge 18+
On mobile, passkeys integrate with the platform’s credential manager (iCloud Keychain on iOS, Google Password Manager on Android). @stwd/react-native exposes native bridge helpers for passkey login, registration, and MFA step-up: your app supplies a platform credential-manager adapter with startAuthentication() and startRegistration(), and Steward handles the API challenge/verification/session exchange.