Skip to main content
The web login and enrollment components return clientState in their completion callbacks. It carries SDK context used for returning-user experiences, including a client environment handle and information about the last login. The SDK maintains its own state in the browser’s localStorage. If your integration separately persists the returned string, pass it through the login component’s optional clientState property when mounting it again. See the login example. Treat the string as opaque SDK data rather than depending on its internal fields. Its encoding is not encryption, and it can contain an account identifier. Avoid including it in public URLs or routine application logs. Client state does not prove that a passkey is still available and does not authenticate the user. Your backend must verify signedPasskeyData before creating a session. Clearing browser storage can remove remembered context without removing the user’s passkey from their credential provider. Include account switching and shared-device behavior in your integration plan. One-Tap should provide a way to use another account, and your application should keep its own session and sign-out policy separate from SDK state.