# Support passwordless login with Passkeys

**URL:** https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259
**Category:** Feature
**Tags:** completed, passkey
**Created:** [June 7, 2022, 1:10am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259 "2022-06-07T01:10:40Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![TheDarkWizard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thedarkwizard/32/177913_2.png) [@TheDarkWizard](https://meta.discourse.org/u/TheDarkWizard)
#### Post date: [June 7, 2022, 1:10am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/1 "2022-06-07T01:10:41Z")

</div>

Hi,

I’m suggesting support for Apple’s Passkeys system.

> **[Supporting passkeys | Apple Developer Documentation](https://developer.apple.com/documentation/authenticationservices/supporting-passkeys)**
>
> Eliminate passwords for your users when they sign in to apps and websites.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [June 7, 2022, 5:02am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/2 "2022-06-07T05:02:48Z")

</div>

What’s the big leap over [Discourse Apple Authentication](https://meta.discourse.org/t/sign-in-with-apple-plugin/171485)?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [June 7, 2022, 6:02am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/3 "2022-06-07T06:02:48Z")

</div>

> **[Google, Apple, Microsoft make a new commitment for a "passwordless future"](https://www.zdnet.com/article/google-apple-microsoft-make-a-new-commitment-for-a-passwordless-future/)**
>
> Passwords may soon be a thing of the past now that these major tech companies have extended support for passwordless FIDO sign-in standards.

> However, under previous implementations, users have to sign into each website or app with each device before they can use passwordless functionality. With this extended commitment, users will be able to automatically access their passkey on many of their devices, even new ones, without having to re-enroll every account. Additionally, people will be able to use FIDO authentication on their mobile device to sign into an app or website on a nearby device, regardless of the OS platform or browser they’re running.

I guess it is just a refined protocol. I am sure we will get to it closer to the new ios release.

---

<div class="post-metadata">

### Author: ![Decorbuz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/decorbuz/32/235124_2.png) [@Decorbuz](https://meta.discourse.org/u/Decorbuz)
#### Post date: [June 7, 2022, 4:03pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/4 "2022-06-07T16:03:49Z")

</div>

> [@TheDarkWizard](#):
>
> Hi,
> 
> I’m suggesting support for Apple’s Passkeys system.
> 
> [https://developer.apple.com/documentation/authenticationservices/public-private\_key\_authentication/supporting\_passkeys](https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication/supporting_passkeys)

I didn’t realize that this is something that CDCK has to implement themselves. I thought it was dependent on the web browser or operating system?

And just to be clear, passkeys aren’t a standard made by Apple. They were made by the [FIDO Alliance](https://en.wikipedia.org/wiki/FIDO_Alliance). Apple is just one of many companies that’s adopting the standard.

> **[Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to...](https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/)**
>
> Faster, easier and more secure sign-ins will be available to consumers across leading devices and platforms 

> [@merefield](#):
>
> What’s the big leap over [Sign in with Apple Plugin](https://meta.discourse.org/t/sign-in-with-apple-plugin/171485)?

Passkeys aren’t a form of SSO.

[![](https://global.discourse-cdn.com/meta/original/4X/0/d/7/0d77c932b8ba52d38a530a3200971ecfb63c4e56.jpeg "WWDC 2022 - June 6 | Apple") ](https://www.youtube.com/watch?v=q5D55G7Ejs8&t=4752)

> [@sam](#):
>
> I guess it is just a refined protocol. I am sure we will get to it closer to the new ios release.

Apple’s implementation seemed much more different and interesting, but maybe I misinterpreted something during the keynote… 🤔

I’m excited to see how this develops once Apple releases its new operating system versions.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [June 7, 2022, 4:14pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/5 "2022-06-07T16:14:48Z")

</div>

Involving a kind public/private key cryptography?

I’m always wary when Apple is involved because they love to create proprietary schemes to keep you stuck in their ecosystem …

---

<div class="post-metadata">

### Author: ![TheDarkWizard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thedarkwizard/32/177913_2.png) [@TheDarkWizard](https://meta.discourse.org/u/TheDarkWizard)
#### Post date: [June 7, 2022, 5:19pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/6 "2022-06-07T17:19:24Z")

</div>

It’s supposed to be based on an open standard by the fido alliance. Google, Microsoft, and other major platforms are also on board.

Apple claims on its site that it will work with non-apple devices but gives no explanation on how they will accomplish that.

---

<div class="post-metadata">

### Author: ![Decorbuz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/decorbuz/32/235124_2.png) [@Decorbuz](https://meta.discourse.org/u/Decorbuz)
#### Post date: [June 7, 2022, 6:19pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/7 "2022-06-07T18:19:32Z")

</div>

> [@merefield](#):
>
> Involving a kind public/private key cryptography?

It’s supposed to only work on your devices.

> [@merefield](#):
>
> I’m always wary when Apple is involved because they love to create proprietary schemes to keep you stuck in their ecosystem …

Thankfully, this isn’t it. It’s an _open_ standard. 😁

> [@TheDarkWizard](#):
>
> Apple claims on its site that it will work with non-apple devices but gives no explanation on how they will accomplish that.

Apple won’t know how Microsoft and Google implement it until they do so.

---

<div class="post-metadata">

### Author: ![Saklad5](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@Saklad5](https://meta.discourse.org/u/Saklad5)
#### Post date: [September 27, 2022, 7:29pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/8 "2022-09-27T19:29:33Z")

</div>

As discussed, passkeys are **not** Apple’s own system. They aren’t even a proper noun.

Passkeys are actually already supported by Discourse, albeit imperfectly: they take the form of WebAuthn security keys. The only change Discourse needs to make to support them properly is allowing a security key to be used **instead** of a password, rather than as a form of two-factor authentication.

* * *

Apple has a [video](https://developer.apple.com/videos/play/wwdc2022/10092/?time=305) about how to implement the UX, and I’m sure many other companies do too, but I’ll summarize the relevant points here.

To implement perfect support for passkeys (hereafter referred to as “registered security keys”), Discourse only needs to make the following changes:

1. Change the sign-in modal to only show the password field if the user enters the email address of an account **without** registered security keys. Passkeys should be presented as the default, not passwords. If the user has both, treat the password as a backup option: since passkeys have a system for authenticating other devices, the **only** reason you’d use a password is if the browser is too old to implement passkey support at all. This will become increasingly uncommon.
2. Accept a registered security key as the sole source of authentication: do not prompt for a password, do not use any multi-factor authentication methods. There is no point requiring a TOTP code, as anyone with the WebAuthn private key would also have the TOTP shared secret used to generate one-time codes. The latter is actually much easier to steal, as it is generated by the Discourse instance in the first place: it’s a **shared** secret.
3. Allow users with registered security keys to remove their passwords.
4. Only use two-factor authentication methods if the user uses a password.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [September 27, 2022, 7:46pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/9 "2022-09-27T19:46:58Z")

</div>

> [@Saklad5](#):
>
> The only change Discourse needs to make to support them properly is allowing a security key to be used **instead** of a password, rather than as a form of two-factor authentication.

That was covered in our original spec for webauthn

> [@Webauthn support](https://meta.discourse.org/t/webauthn-support/126454/1):
>
> ### Authentication Methods
> 
> - Webauthn as a second factor authenticator (act like a Google Authenticator alternative)
> - Webauthn as a first factor authenticator (act like a social login alternative)
> - Webauthn as a multi factor authenticator (username-less login)

However we only implemented the first, and most common webauthn method.

> [@Webauthn support](https://meta.discourse.org/t/webauthn-support/126454/5):
>
> I would very much like to avoid even thinking about “First factor / passwordless” auth here, to me we got to ship this feature and live with it for 3-4 months before even considering this.

---

<div class="post-metadata">

### Author: ![Saklad5](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@Saklad5](https://meta.discourse.org/u/Saklad5)
#### Post date: [September 27, 2022, 7:52pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/10 "2022-09-27T19:52:06Z")

</div>

Well, first factor WebAuthn is called “passkeys” now, and it’s time to start considering this.

To illustrate that they are the same thing, this is what logging into Tor Project’s Discourse instance through Safari currently looks like in iOS 16, once I’ve entered an email and password:

 ![Passkey](https://global.discourse-cdn.com/meta/original/4X/f/5/a/f5a0ad1e2a511f8836f02d78c77ed047dc153f1a.jpeg)

---

<div class="post-metadata">

### Author: ![Saklad5](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@Saklad5](https://meta.discourse.org/u/Saklad5)
#### Post date: [September 27, 2022, 7:58pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/11 "2022-09-27T19:58:07Z")

</div>

And in Safari on macOS Monterey (which is a year older), using the same key:

 ![image](https://global.discourse-cdn.com/meta/original/4X/0/2/a/02a33cc4e92c61cefcd6c0cdfdb0bc680c480b59.png)

I suspect macOS Ventura will change the language to match iOS 16.

That’s the main innovation over existing WebAuthn from the user’s perspective, by the way: you can synchronize the private key using an end-to-end encrypted password manager of your choice.

---

<div class="post-metadata">

### Author: ![dfabulich](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dfabulich/32/108716_2.png) [@dfabulich](https://meta.discourse.org/u/dfabulich)
#### Post date: [September 27, 2022, 10:04pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/12 "2022-09-27T22:04:14Z")

</div>

It’s been well over 3-4 months by now, hasn’t it? So enabling first factor support could be a thing?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [September 27, 2022, 10:48pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/13 "2022-09-27T22:48:44Z")

</div>

I am ok to add this as an opt in admin option, but do not think we have bandwidth to work on this for a month or 2

---

<div class="post-metadata">

### Author: ![Decorbuz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/decorbuz/32/235124_2.png) [@Decorbuz](https://meta.discourse.org/u/Decorbuz)
#### Post date: [September 29, 2022, 3:10am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/14 "2022-09-29T03:10:55Z")

</div>

Would somebody be willing to fund it in #Marketplace?

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [October 12, 2022, 4:52pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/15 "2022-10-12T16:52:04Z")

</div>

Coming to Android too

> **[Security of Passkeys in the Google Password Manager](https://security.googleblog.com/2022/10/SecurityofPasskeysintheGooglePasswordManager.html)**
>
> Posted by Arnar Birgisson, Software Engineer We are excited to announce passkey support on Android and Chrome for developers to test today, ...

---

<div class="post-metadata">

### Author: ![Decorbuz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/decorbuz/32/235124_2.png) [@Decorbuz](https://meta.discourse.org/u/Decorbuz)
#### Post date: [October 13, 2022, 1:38am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/16 "2022-10-13T01:38:25Z")

</div>

I’d be willing to bet that Microsoft’s implementation will find its way into Windows by the end of the year.

> **[Reminder: passkeys are not just from Apple](https://www.theverge.com/2022/8/5/23293643/apple-passkeys-fido-alliance-passwordless-google-microsoft)**
>
> Microsoft and Google will also use the term.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [October 28, 2022, 9:54pm UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/17 "2022-10-28T21:54:36Z")

</div>

Once we have Android and iOS support, I think that is a clear mandate to implement it for Discourse.. since it has shipped on the Apple side we are waiting for Android now.

> **[Bringing passkeys to Android & Chrome](https://android-developers.googleblog.com/2022/10/bringing-passkeys-to-android-and-chrome.html)**
>
> developers can enroll in the Google Play Services beta and use Chrome Canary. Both features will be generally available on stable channels

> Two features are being announced today for early adopters that enroll in the [Google Play Services beta](https://developers.google.com/android/guides/beta-program) and use [Chrome Canary](https://www.google.com/chrome/canary/), with a stable launch coming “later this year”:

The article was written _this month_, so it might ship by the end of 2022?

---

<div class="post-metadata">

### Author: ![anon62397346](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@anon62397346](https://meta.discourse.org/u/anon62397346)
#### Post date: [December 11, 2022, 5:50am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/20 "2022-12-11T05:50:23Z")

</div>

Update

- Passkeys are [now](https://blog.chromium.org/2022/12/introducing-passkeys-in-chrome.html) stable on chromium. (Note: Firefox does not support passkeys yet)
- Password managers like Dashlane, 1password announced support for passkeys

 ![image](https://global.discourse-cdn.com/meta/original/4X/f/3/9/f391161f6026d96b048f800afe0de180a459b1af.png)

This is what passkeys support looks like as of Dec 11.

source: [Passkey support on Android and Chrome &nbsp;|&nbsp; Passkeys &nbsp;|&nbsp; Google for Developers](https://developers.google.com/identity/passkeys/supported-environments)

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [January 19, 2023, 4:55am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/22 "2023-01-19T04:55:08Z")

</div>

Also, there is a cool demo video on the [https://www.passwordless.dev/](https://www.passwordless.dev/) website

---

<div class="post-metadata">

### Author: ![000](https://avatars.discourse-cdn.com/v4/letter/0/258eb7/32.png) [@000](https://meta.discourse.org/u/000)
#### Post date: [April 23, 2023, 12:15am UTC](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259/24 "2023-04-23T00:15:07Z")

</div>

> [@codinghorror](#):
>
> Once we have Android and iOS support, I think that is a clear mandate to implement it for Discourse… since it has shipped on the Apple side we are waiting for Android now.

I think android is support passkeys now

[Next page](https://meta.discourse.org/t/support-passwordless-login-with-passkeys/229259.md?page=2)
