# Webauthn support

**URL:** https://meta.discourse.org/t/webauthn-support/126454
**Category:** Feature
**Tags:** rfc
**Created:** [August 21, 2019, 11:20pm UTC](https://meta.discourse.org/t/webauthn-support/126454 "2019-08-21T23:20:40Z")
**Posts on this page:** 8
**Page:** 3

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [August 24, 2020, 2:08am UTC](https://meta.discourse.org/t/webauthn-support/126454/43 "2020-08-24T02:08:19Z")

</div>

It is going to be very interesting to see if you can enter your faceid on the phone and login using the web browser on the desktop. We are probably going to need some creative changes to support that.

@martin worth bookmarking this to have a look in say 2 months when iOS 14 is released.

---

<div class="post-metadata">

### Author: ![martin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/martin/32/491371_2.png) [@martin](https://meta.discourse.org/u/martin)
#### Post date: [August 24, 2020, 2:10am UTC](https://meta.discourse.org/t/webauthn-support/126454/44 "2020-08-24T02:10:27Z")

</div>

I am not sure we will need to do anything, because we already support multiple security keys (it annoys me very much now that sites like AWS do not support multiple 2FA methods…). Falco’s lovely face is just considered another key 🙂. Nevertheless I will try it out and see whether I need to do anything when iOS 14 comes out, setting a reminder. I am excited for this feature!

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [August 24, 2020, 2:15am UTC](https://meta.discourse.org/t/webauthn-support/126454/45 "2020-08-24T02:15:52Z")

</div>

I was more thinking that people with iPhones get double plus security, cause the can use the iPhone for free with no Yubikey or anything to perform 2fa for them.

How it could work is that we would “simulate” it using the app. EG:

- You log in with username / password
- You would pick your iPhone for 2fa
- Desktop would pop up, please authorize usage by typing 173405 into you mobile app
- You would type that on the phone, it would do a face id, then authorize access for the desktop

Something crazy like that, still very much in the brainstorming phase.

---

<div class="post-metadata">

### Author: ![martin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/martin/32/491371_2.png) [@martin](https://meta.discourse.org/u/martin)
#### Post date: [August 24, 2020, 2:17am UTC](https://meta.discourse.org/t/webauthn-support/126454/46 "2020-08-24T02:17:16Z")

</div>

Ah I see, like how if you have the Gmail app on your phone you can use the popup it shows as a 2FA device with approval to log into Gmail.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [August 30, 2021, 8:42pm UTC](https://meta.discourse.org/t/webauthn-support/126454/47 "2021-08-30T20:42:07Z")

</div>

4 posts were split to a new topic: [QR Code Login method](https://meta.discourse.org/t/qr-code-login-method/202164)

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [October 19, 2020, 8:06pm UTC](https://meta.discourse.org/t/webauthn-support/126454/52 "2020-10-19T20:06:33Z")

</div>

> [@sam](#):
>
> I would very much like to avoid even thinking about “First factor / passwordless” auth here, to me we got to ship this feature and live with it for 3-4 months before even considering this.

14 months later…

Username-less and Password-less logins will be natively supported on iOS devices, making this method accessible to a much wider audience now:

> **[Meet Face ID and Touch ID for the Web](https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-the-web/)**
>
> People often see passwords are the original sin of authentication on the web.

Login by FaceID without having to type **anything** (nor username or password) would make sessions more secure and less cumbersome.

---

<div class="post-metadata">

### Author: ![martin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/martin/32/491371_2.png) [@martin](https://meta.discourse.org/u/martin)
#### Post date: [October 19, 2020, 11:12pm UTC](https://meta.discourse.org/t/webauthn-support/126454/53 "2020-10-19T23:12:16Z")

</div>

I just set up my face as a “security key” 2FA method here on Meta, this is so cool and works really well! I would love to work on the passwordless auth for this at some point cc @sam . Crazy that it has been a year since I first worked on this!

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [November 3, 2020, 6:57am UTC](https://meta.discourse.org/t/webauthn-support/126454/54 "2020-11-03T06:57:56Z")

</div>

I am closing this as done, we completed this so long ago!

[Previous page](https://meta.discourse.org/t/webauthn-support/126454.md?page=2)
