Skip to main content
theauth-go ships a WebAuthn / passkey implementation that covers discoverable login, sign-count replay protection, and single-factor-strong per NIST SP 800-63B.

Configure

WebAuthnConfig.RPID must be the eTLD+1 of your domain. For local development use localhost and https://localhost:8080 as origin.

Endpoints

a.Mount(r) wires these routes when Config.WebAuthn is set:

Registration flow (client side)

Discoverable login flow (client side)

Sign-count replay protection

theauth-go checks that the new sign count is strictly greater than the stored count on every login. If not, it returns ErrReplayDetected. The carve-out: authenticators that do not implement counters (they return count=0 always) are allowed because the WebAuthn spec requires it.

NIST 800-63B compliance

A successfully verified passkey assertion constitutes a single-factor-strong authentication event. When combined with a password (or other factor), it satisfies multi-factor authentication per NIST SP 800-63B AAL2.

Runnable example

See examples/webauthn-passkey/ for a full demo with HTML UI.
Last modified on October 7, 2026