Try Demo
Talk to Adoption Engineer
Whitepaper
signedPasskeyData is a short-lived, single-use JSON Web Token (JWT) that confirms a successful passkey authentication with Corbado Connect:
signedPasskeyData, it should be sent to your application’s backend for verification. Your backend then calls a Corbado Backend API endpoint to verify the token’s authenticity. If the verification is successful, your backend can proceed to create a session for the user.
This process ensures that the passkey login is valid and securely transfers the authentication status from Corbado to your application.
The flow looks as follows:
- Corbado Connect login: A user logs in using their passkey in a web or native/mobile application.
signedPasskeyDatais returned: Upon successful passkey authentication, Corbado’s Frontend API returns asignedPasskeyDatatoken to your web or native/mobile application.- Backend verification:
Your web or native/mobile application sends the
signedPasskeyDatato your backend. Your backend then makes a secure server-to-server API call to Corbado’s/v2/passkey/verifySignedDataendpoint withsignedPasskeyDataandusernameset to the JWT’swebauthnIdclaim. Decoded claims remain untrusted until the API returnsverificationResult: "success"(see API Reference). - Session creation:
After successful verification, resolve
webauthnIdto the existing account in your authentication system and create its session. The JWT’ssubis Corbado’s internal user ID, so do not use it as your application’s user ID without an explicit mapping. - Short-lived & single use:
Each
signedPasskeyDatatoken is short-lived and can be used only once for verification. This prevents replay attacks and ensures a high level of security.
signedPasskeyData to securely establish a session.