Is your WebAuthn config set up for strong passkeys?
Paste the publicKey options your relying party hands to navigator.credentials.create() or .get(). passkeycheck detects which one
it is and checks it against W3C WebAuthn Level 3 and current passkeys.dev guidance — challenge
entropy, rp.id validity, user verification, algorithms and attestation. Runs entirely
in your browser; nothing is stored unless you save the report.
Load example:
The options JSON is relying-party configuration, not a credential or secret — but it is still analyzed entirely in your browser.