SimpleWebAuthn

Verify passkey registration and authentication ceremonies through Playstack's optional Node.js WebAuthn adapter.

Visit SimpleWebAuthn ↗

Supported features

Authentication

Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.

Passkeys and MFA

Package reference

@playstack/mfa

Add standards-level ceremony verification

@playstack/mfa/webauthn adapts @simplewebauthn/server to Playstack's PasskeyAdapter. Playstack retains challenge lifetime and single use, credential uniqueness, sign-count persistence, and the application's exact origin and relying-party expectations.

ts
import { createMfa } from '@playstack/mfa'
import { simpleWebAuthnPasskeys } from '@playstack/mfa/webauthn'

const passkeys = simpleWebAuthnPasskeys({
  userVerification: 'required',
  residentKey: 'preferred',
})

const mfa = createMfa({
  passkeys,
  rpId: 'app.example.com',
  rpName: 'Example',
  origins: ['https://app.example.com'],
  // Persistence, crypto, events, limits, time, and identifiers stay explicit.
})

The adapter defaults user verification to required, prefers discoverable credentials, requests no attestation, and supports multiple exact origins. The portable MFA core remains usable with another standards implementation through the same explicit adapter seam.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software