# Error when create user passkey in browser

**URL:** https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434
**Category:** Support
**Tags:** passkey
**Created:** [August 13, 2025, 1:52pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434 "2025-08-13T13:52:04Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [August 13, 2025, 1:52pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/1 "2025-08-13T13:52:04Z")

</div>

when i try to create passkey in my own site, it reminds

```plaintext
The passkey registration process either timed out, was cancelled or is not allowed

```

but i can create passkey in discourse meta forum in same browser(mirosoft edge) and same plugin( apple passkey)

i have upgraded my discourse to latest, but it doesn’t work like [this post](https://meta.discourse.org/t/issues-using-passkeys-with-vaultwarden/294865)

---

<div class="post-metadata">

### Author: ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)
#### Post date: [August 14, 2025, 3:33am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/2 "2025-08-14T03:33:10Z")

</div>

Hey, it looks like we do show a [console error](https://github.com/discourse/discourse/blob/d2cd9462ba3b68763ef53a333743f51ac344d4d3/app/assets/javascripts/discourse/app/components/user-preferences/user-passkeys.gjs#L102-L110) when this message you share shows up in a dialog.

Could you open your browser console and share with us the error you might see?

---

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [August 14, 2025, 5:29am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/3 "2025-08-14T05:29:51Z")

</div>

![image](https://global.discourse-cdn.com/meta/original/4X/2/b/e/2bef53534582ff7e1e4253fc346241ff97a0f251.png)  
it seems like there is nothing about this error in logs

---

<div class="post-metadata">

### Author: ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)
#### Post date: [August 14, 2025, 5:48am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/4 "2025-08-14T05:48:40Z")

</div>

You’ll need to see your browser console log, not site /logs.

 ![console log](https://global.discourse-cdn.com/meta/original/4X/a/0/d/a0d7d54eba92383b599b833d27ea9ab5d64e45fe.jpeg)

---

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [August 14, 2025, 11:48am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/5 "2025-08-14T11:48:23Z")

</div>

is this right?

 ![image](https://global.discourse-cdn.com/meta/original/4X/d/0/6/d067c430f0167172e3276f3248aec7f7499ecf6c.png)

```plaintext
forum.beginner.center/:1 Mixed Content: The page at 'https://forum.beginner.center/' was loaded over HTTPS, but requested an insecure font 'http://forum.beginner.center/fonts/JetBrainsMono-Regular.woff2?v=0.0.19'. This request has been blocked; the content must be served over HTTPS.
forum.beginner.center/:1 Mixed Content: The page at 'https://forum.beginner.center/' was loaded over HTTPS, but requested an insecure font 'http://forum.beginner.center/fonts/JetBrainsMono-Bold.woff2?v=0.0.19'. This request has been blocked; the content must be served over HTTPS.
app.js:270 ℹ️ Discourse v3.5.0.beta9-dev — https://github.com/discourse/discourse/commits/33dfd7dba9 — Ember v5.12.0
[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'nonce-4YvvTZffYuqGaENC8DnQ7yeNg' 'strict-dynamic'".

analytics.eu.umami.is/script.js:1 Failed to load resource: net::ERR_CONNECTION_CLOSED
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
Tracking Prevention blocked access to storage for <URL>.
deprecated.js:62 Deprecation notice: Setting timezone property of user object is deprecated. Use user_option object instead [deprecated since Discourse 2.9.0.beta12] [removal in Discourse 3.0.0.beta1] [deprecation id: discourse.user.userOptions]
a @ deprecated.js:62
security:1 Autofocus processing was blocked because a document already has a focused element.
completion_list.html:14 GET chrome-extension://mfbcdcnpokpoajjciilocoachedjkima/heuristicsRedefinitions.js net::ERR_FILE_NOT_FOUND
completion_list.html:13 GET chrome-extension://mfbcdcnpokpoajjciilocoachedjkima/extensionState.js net::ERR_FILE_NOT_FOUND
completion_list.html:12 GET chrome-extension://mfbcdcnpokpoajjciilocoachedjkima/utils.js net::ERR_FILE_NOT_FOUND
ajax.js:188 POST https://forum.beginner.center/u/register_passkey.json 401 (Unauthorized)
send @ jquery.js:9940
ajax @ jquery.js:9521
o @ ajax.js:188
(匿名) @ rsvp-DaQAFb0W.js:435
e @ rsvp-DaQAFb0W.js:451
A @ ajax.js:201
registerPasskey @ user.js:650
createPasskey @ user-passkeys.gjs:86
await in createPasskey
didConfirm @ user-passkeys.gjs:140
didConfirmWrapped @ dialog.js:134
_join @ index.js:788
join @ index.js:605
p @ index.js:152
(匿名) @ index.js:250
submit @ confirm-session.gjs:84
await in submit
(匿名) @ d-button.gjs:138
invoke @ index.js:264
flush @ index.js:180
flush @ index.js:334
_end @ index.js:762
end @ index.js:565
_runExpiredTimers @ index.js:869
setTimeout
setTimeout @ index.js:39
_installTimerTimeout @ index.js:912
_later @ index.js:823
later @ index.js:652
T @ index.js:562
_triggerAction @ d-button.gjs:135
click @ d-button.gjs:93
user-passkeys.gjs:104 {jqXHR: {…}, textStatus: 'error', errorThrown: ''}errorThrown: ""jqXHR: abort: ƒ (e)always: ƒ ()catch: ƒ (e)done: ƒ ()fail: ƒ ()getAllResponseHeaders: ƒ ()getResponseHeader: ƒ (e)jqTextStatus: "error"overrideMimeType: ƒ (e)pipe: ƒ ()progress: ƒ ()promise: ƒ (e)readyState: 4requestedUrl: "/u/register_passkey.json"responseJSON: {errors: Array(1)}responseText: "{\"errors\":[\"The origin of the authentication request does not match the server origin.\"]}"setRequestHeader: ƒ (e,t)state: ƒ ()status: 401statusCode: ƒ (e)statusText: "error"then: ƒ (e,i,n)[[Prototype]]: ObjecttextStatus: "error"[[Prototype]]: Objectconstructor: ƒ Object()hasOwnProperty: ƒ hasOwnProperty()isPrototypeOf: ƒ isPrototypeOf()propertyIsEnumerable: ƒ propertyIsEnumerable()toLocaleString: ƒ toLocaleString()toString: ƒ toString()valueOf: ƒ valueOf() __defineGetter__ : ƒ __defineGetter__ () __defineSetter__ : ƒ __defineSetter__ () __lookupGetter__ : ƒ __lookupGetter__ () __lookupSetter__ : ƒ __lookupSetter__ () __proto__ : (...)get __proto__ : ƒ __proto__ ()set __proto__ : ƒ __proto__ ()
createPasskey @ user-passkeys.gjs:104
await in createPasskey
didConfirm @ user-passkeys.gjs:140
didConfirmWrapped @ dialog.js:134
_join @ index.js:788
join @ index.js:605
p @ index.js:152
(匿名) @ index.js:250
submit @ confirm-session.gjs:84
await in submit
(匿名) @ d-button.gjs:138
invoke @ index.js:264
flush @ index.js:180
flush @ index.js:334
_end @ index.js:762
end @ index.js:565
_runExpiredTimers @ index.js:869
setTimeout
setTimeout @ index.js:39
_installTimerTimeout @ index.js:912
_later @ index.js:823
later @ index.js:652
T @ index.js:562
_triggerAction @ d-button.gjs:135
click @ d-button.gjs:93

```

---

<div class="post-metadata">

### Author: ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)
#### Post date: [August 14, 2025, 1:57pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/6 "2025-08-14T13:57:17Z")

</div>

> [@whitewaterdeu](#):
>
> `POST https://forum.beginner.center/u/register_passkey.json 401 (Unauthorized)`

Oh hmm this is useful but 401s can be triggered by a myriad of reasons. Will check with our resident passkeys expert.

---

<div class="post-metadata">

### Author: ![pmusaraj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pmusaraj/32/119489_2.png) [@pmusaraj](https://meta.discourse.org/u/pmusaraj)
#### Post date: [August 14, 2025, 2:03pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/8 "2025-08-14T14:03:18Z")

</div>

Can you make sure your site is configured to serve everything in https? Passkey challenge verification requires that all requests go through https. Also the domain between browser and server must match exactly. If there is a mismatch somewhere, the verification will fail.

We have a setting for this, `force_https`, you can try that, it may help (though be careful, it might also lock you out if server isn’t configured properly).

---

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [August 15, 2025, 2:33am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/9 "2025-08-15T02:33:38Z")

</div>

this is my `app.yml`  
i am using reverse proxy by OpenResty (based on nginx)

```plaintext
expose:
  - "6180:80" # http
  - "6443:443" # https
  - "587:587"

```

i can’t use my site by https port 6443

 ![image](https://global.discourse-cdn.com/meta/original/4X/2/9/6/2964a2abdd44f48103d47727c3f7fa638d5a1ed9.jpeg)

so i only set reverse proxy of http

this is my OpenResty config

```plaintext
server {
    listen 80 ; 
    listen 443 ssl http2 ; 
    server_name forum.beginner.center; 
    index index.php index.html index.htm default.php default.htm default.html; 
    proxy_set_header Host $host; 
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; 
    proxy_set_header X-Forwarded-Host $server_name; 
    proxy_set_header X-Real-IP $remote_addr; 
    proxy_http_version 1.1; 
    proxy_set_header Upgrade $http_upgrade; 
    proxy_set_header Connection $http_connection; 
    access_log /www/sites/forum.beginner.center/log/access.log main; 
    error_log /www/sites/forum.beginner.center/log/error.log; 
    location ^~ /.well-known/acme-challenge {
        allow all; 
        root /usr/share/nginx/html; 
    }
    if ($scheme = http) {
        return 301 https://$host$request_uri; 
    }
    ssl_certificate /www/sites/forum.beginner.center/ssl/fullchain.pem; 
    ssl_certificate_key /www/sites/forum.beginner.center/ssl/privkey.pem; 
    ssl_protocols TLSv1.3 TLSv1.2 TLSv1.1 TLSv1; 
    ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:!aNULL:!eNULL:!EXPORT:!DSS:!DES:!RC4:!3DES:!MD5:!PSK:!KRB5:!SRP:!CAMELLIA:!SEED; 
    ssl_prefer_server_ciphers on; 
    ssl_session_cache shared:SSL:10m; 
    ssl_session_timeout 10m; 
    error_page 497 https://$host$request_uri; 
    proxy_set_header X-Forwarded-Proto https; 
    add_header Strict-Transport-Security "max-age=31536000"; 
    include /www/sites/forum.beginner.center/proxy/*.conf; 
}

```

this is reverse proxy config

```plaintext
location ^~ / {
    proxy_pass http://127.0.0.1:6180; 
    proxy_set_header Host $host; 
    proxy_set_header X-Real-IP $remote_addr; 
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; 
    proxy_set_header REMOTE-HOST $remote_addr; 
    proxy_set_header Upgrade $http_upgrade; 
    proxy_set_header Connection $http_connection; 
    proxy_set_header X-Forwarded-Proto $scheme; 
    proxy_http_version 1.1; 
    add_header X-Cache $upstream_cache_status; 
    add_header Cache-Control no-cache; 
    proxy_ssl_server_name off; 
    proxy_ssl_name $proxy_host; 
    add_header Strict-Transport-Security "max-age=31536000"; 
}

```

---

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [August 17, 2025, 1:04pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/10 "2025-08-17T13:04:46Z")

</div>

hello， anyone can help me？

---

<div class="post-metadata">

### Author: ![pmusaraj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pmusaraj/32/119489_2.png) [@pmusaraj](https://meta.discourse.org/u/pmusaraj)
#### Post date: [August 18, 2025, 8:35pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/11 "2025-08-18T20:35:41Z")

</div>

Sorry for the delay. The issue here is indeed related to your proxy. I can’t exactly say what it is, but one of domain name, protocol (http or https) and port are getting in the way.

Passkeys verify that the frontend and backend both run on the same domain, protocol and port. If one of these is a mismatch, you’ll get an error like this.

In the Rails CLI, can you try this:

```plaintext
DiscourseWebauthn.origin

```

and compare it to the URL that you use to access the site in the browser? The two should match.

---

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [October 26, 2025, 4:11pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/12 "2025-10-26T16:11:40Z")

</div>

user passkey function worked when i enable `force https`

# reference

> [@Discourse ID fails to activate on my instance](https://meta.discourse.org/t/discourse-id-fails-to-activate-on-my-instance/386023):
>
> I see this message when I try to activate Discourse\_id on my test system (3.6.0.beta2-latest): enable\_discourse\_id: You must configure Discourse ID credentials ('discourse\_id\_client\_id' and 'discourse\_id\_client\_secret') before enabling this setting. I use a local Oauth server for OIDC here (keycloak). Maybe the two methods are interfering with each other??

---

<div class="post-metadata">

### Author: ![Thomas\_Rother](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thomas_rother/32/423597_2.png) [@Thomas\_Rother](https://meta.discourse.org/u/Thomas_Rother)
#### Post date: [October 29, 2025, 12:29pm UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/13 "2025-10-29T12:29:02Z")

</div>

> [@whitewaterdeu](#):
>
> passkey

As far as I understand the Webauthn Standard for Passkey, it relies on a secure connection between the Relying Party (Discourse) and the Client (Browser or mobile device) and the Authenticator (e.g. a yubikey). Thus we need https for the communication coming from the Discourse application. Forcing https may be the solution, but just a header for

proxy\_set\_header X-Forwarded-Proto `https;`

could also be enough. If forcing of https helps (which is recommended anyway), all is fine.

---

<div class="post-metadata">

### Author: ![whitewaterdeu](https://avatars.discourse-cdn.com/v4/letter/w/57b2e6/32.png) [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)
#### Post date: [October 30, 2025, 6:40am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/14 "2025-10-30T06:40:21Z")

</div>

i don’t know how to config `proxy_set_header X-Forwarded-Proto`

in `app.yaml`?

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [November 29, 2025, 6:40am UTC](https://meta.discourse.org/t/error-when-create-user-passkey-in-browser/378434/15 "2025-11-29T06:40:25Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
