Skip to content

basalt / auth/src / WebAuthnService

Class: WebAuthnService ​

Defined in: auth/src/webauthn.ts:304

Constructors ​

Constructor ​

> new WebAuthnService(options): WebAuthnService

Defined in: auth/src/webauthn.ts:312

Parameters ​

options ​

WebAuthnServiceOptions

Returns ​

WebAuthnService

Methods ​

finishAuthentication() ​

> finishAuthentication(sessionKey, response): Promise<{ credentialId: string; userId: string; }>

Defined in: auth/src/webauthn.ts:443

Verify an authentication response. Looks the credential up by its id, checks the signature counter increased (clone detection), persists the new counter with a compare-and-set (so two concurrent assertions cannot both pass), and returns whose passkey authenticated. Throws on any failure.

Parameters ​

sessionKey ​

string

response ​

unknown

Returns ​

Promise<{ credentialId: string; userId: string; }>


finishRegistration() ​

> finishRegistration(sessionKey, userId, response, deviceName?): Promise<PasskeyCredential>

Defined in: auth/src/webauthn.ts:374

Verify a registration response and store the new passkey. Throws on failure.

Parameters ​

sessionKey ​

string

userId ​

string

response ​

unknown

deviceName? ​

string

Returns ​

Promise<PasskeyCredential>


list() ​

> list(userId): Promise<PasskeyCredential[]>

Defined in: auth/src/webauthn.ts:495

A user's registered passkeys (for a "manage devices" screen).

Parameters ​

userId ​

string

Returns ​

Promise<PasskeyCredential[]>


remove() ​

> remove(userId, credentialId): Promise<void>

Defined in: auth/src/webauthn.ts:504

Remove one of userId's passkeys (revoke a device). The credential must belong to userId: a credential id is not an authorization, so an id that is unknown or owned by another user throws PasskeyNotFoundError (the same error for both, so the call cannot probe other users' devices).

Parameters ​

userId ​

string

credentialId ​

string

Returns ​

Promise<void>


startAuthentication() ​

> startAuthentication(sessionKey, userId?): Promise<AuthenticationOptions>

Defined in: auth/src/webauthn.ts:421

Authentication options; omit userId for discoverable login. With a userId (step-up, re-authentication) the challenge is bound to that user: finishAuthentication then refuses a passkey that belongs to anyone else, and allowCredentials lists only that user's passkeys.

Parameters ​

sessionKey ​

string

userId? ​

string

Returns ​

Promise<AuthenticationOptions>


startRegistration() ​

> startRegistration(sessionKey, user): Promise<RegistrationOptions>

Defined in: auth/src/webauthn.ts:351

Registration options for a known user; stores the challenge bound to user.id.

Parameters ​

sessionKey ​

string

user ​
displayName? ​

string

id ​

string

name ​

string

Returns ​

Promise<RegistrationOptions>

Released under the MIT License.