{"repo":"AndroidPoet/passkeys-kmp","free":true,"listed":false,"github":"https://github.com/AndroidPoet/passkeys-kmp","clone":"git clone https://github.com/AndroidPoet/passkeys-kmp.git","description":"Kotlin Multiplatform passkeys SDK — one common API with real native authenticators on Android, iOS, macOS, Windows, Linux, Wasm & JVM/Compose Desktop.","language":"Kotlin","stars":35,"topics":["android","authentication","compose-multiplatform","credential-manager","fido2","ios","kotlin","kotlin-multiplatform","passkeys","passwordless"],"license":"MIT","category":"mobile-apps","readme_excerpt":"Passkeys KMP Simple. Secure. Passwordless. One common passkeys API for Kotlin Multiplatform, backed by real native authenticators on Android, iOS, macOS, Windows, Linux, browser (Wasm), and JVM/Compose Desktop. Install Usage One call site, every platform — create / authenticate return a PasskeyResult : Platforms Platform Authenticator Anchor (auto via Compose) One-time setup --- --- --- --- Android (API 28+) Fingerprint / face / PIN Activity assetlinks.json iOS 16+ Face ID / Touch ID UIWindow entitlement + AASA macOS 13+ Touch ID NSWindow entitlement + AASA JVM / Compose Desktop Touch ID (macOS) window handle signed .app + entitlement Browser (Wasm) Platform / security key — HTTPS Windows 10 1903+ Windows Hello / security key HWND — Linux Roaming USB/NFC key only — libfido2 + udev rules 📸 See the native authenticator on each platform Same shared create call, each platform's own native authenticator UI: Android — Credential Manager macOS — Touch ID Browser (Wasm) :---: :---: :---: Domain setup A passkey is bound to your domain, so each platform needs proof you own it. Host these two files under https://your-domain.com/.well-known/ (web just needs HTTPS): Then add the Associated Domains entitlement to your Apple target: Verify on your server The SDK only runs the device ceremony — a passkey is trustworthy only after your backend verifies it . Your server generates a fresh challenge into the options JSON, you pass that to create / authenticate , then POST result.value.rawJson b","default_branch":null,"files":null,"tree":[],"storefront":"/r/AndroidPoet","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/AndroidPoet/passkeys-kmp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}