theauth-go ships a WebAuthn / passkey implementation that covers discoverable login, sign-count replay protection, and single-factor-strong per NIST SP 800-63B.
WebAuthnConfig.RPID must be the eTLD+1 of your domain. For local development use localhost and https://localhost:8080 as origin.
Endpoints
a.Mount(r) wires these routes when Config.WebAuthn is set:
Registration flow (client side)
Discoverable login flow (client side)
Sign-count replay protection
theauth-go checks that the new sign count is strictly greater than the stored count on every login. If not, it returns ErrReplayDetected. The carve-out: authenticators that do not implement counters (they return count=0 always) are allowed because the WebAuthn spec requires it.
NIST 800-63B compliance
A successfully verified passkey assertion constitutes a single-factor-strong authentication event. When combined with a password (or other factor), it satisfies multi-factor authentication per NIST SP 800-63B AAL2.
Runnable example
See examples/webauthn-passkey/ for a full demo with HTML UI. Last modified on October 7, 2026