{"repo":"lbuchs/WebAuthn","free":true,"listed":false,"github":"https://github.com/lbuchs/WebAuthn","clone":"git clone https://github.com/lbuchs/WebAuthn.git","description":"A simple PHP WebAuthn (FIDO2/Passkey) server library","language":"PHP","stars":590,"topics":["webauthn","fido2","php-library","fido","2fa","two-factor-authentication","php-webauthn","safetynet-api","windows-hello","fido2-authenticator"],"license":"MIT","category":"mobile-apps","readme_excerpt":"WebAuthn A simple PHP WebAuthn (FIDO2) server library The goal of this project is to provide a small, lightweight, understandable library to protect logins with passkeys, security keys like Yubico or Solo, fingerprint on Android, or Windows Hello. Manual See / test for a simple usage of this library. Check webauthn.lubu.ch for a working example. Supported attestation statement formats android-key &#x2705; android-safetynet &#x2705; apple &#x2705; fido-u2f &#x2705; none &#x2705; packed &#x2705; tpm &#x2705; [!NOTE] This library supports authenticators that are signed with an X.509 certificate or that are self-attested. ECDAA is not supported. Workflow JAVASCRIPT SERVER ------------------------------------------------------------ REGISTRATION window.fetch ----------------- getCreateArgs navigator.credentials.create processCreate alert ok or fail getGetArgs navigator.credentials.get processGet alert ok or fail [!TIP] This is probably what you want to use if you want secure login for a public website. Indirect attestation The browser may replace the AAGUID and attestation statement with a more privacy-friendly and/or more easily verifiable version of the same data (for example, by employing an anonymization CA). You cannot validate against any root CA if the browser uses an anonymization certificate. This library sets attestation to indirect if you select multiple formats but don't provide any root CA. [!TIP] A hybrid solution. Clients may be discouraged by browser warnings, but ","default_branch":null,"files":null,"tree":[],"storefront":"/r/lbuchs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/lbuchs/WebAuthn/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}