Is your WebAuthn config set up for strong passkeys?

Paste the publicKey options your relying party hands to navigator.credentials.create() or .get(). passkeycheck detects which one it is and checks it against W3C WebAuthn Level 3 and current passkeys.dev guidance — challenge entropy, rp.id validity, user verification, algorithms and attestation. Runs entirely in your browser; nothing is stored unless you save the report.

Load example:

The options JSON is relying-party configuration, not a credential or secret — but it is still analyzed entirely in your browser.

passkeycheck

Grade your WebAuthn relying-party config

by IntegrAuth