Authentication
Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
Passkeys and MFA
Verify passkey registration and authentication ceremonies through Playstack's optional Node.js WebAuthn adapter.
Visit SimpleWebAuthn ↗Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
Passkeys and MFA
@playstack/mfa/webauthn adapts @simplewebauthn/server to Playstack's PasskeyAdapter. Playstack retains challenge lifetime and single use, credential uniqueness, sign-count persistence, and the application's exact origin and relying-party expectations.
import { createMfa } from '@playstack/mfa'
import { simpleWebAuthnPasskeys } from '@playstack/mfa/webauthn'
const passkeys = simpleWebAuthnPasskeys({
userVerification: 'required',
residentKey: 'preferred',
})
const mfa = createMfa({
passkeys,
rpId: 'app.example.com',
rpName: 'Example',
origins: ['https://app.example.com'],
// Persistence, crypto, events, limits, time, and identifiers stay explicit.
})The adapter defaults user verification to required, prefers discoverable credentials, requests no attestation, and supports multiple exact origins. The portable MFA core remains usable with another standards implementation through the same explicit adapter seam.