basalt / auth/src / WebAuthnConfig
Interface: WebAuthnConfig
Defined in: auth/src/webauthn.ts:272
Properties
challengeTtlMs?
> optional challengeTtlMs?: number
Defined in: auth/src/webauthn.ts:280
Challenge TTL in ms. Default 5 minutes.
origin
> origin: string | string[]
Defined in: auth/src/webauthn.ts:278
Expected origin(s), e.g. 'https://example.com'.
pubKeyCredParams?
> optional pubKeyCredParams?: PublicKeyParam[]
Defined in: auth/src/webauthn.ts:291
Override the accepted algorithms. Default ES256 + RS256.
rpId
> rpId: string
Defined in: auth/src/webauthn.ts:274
Relying Party ID — your registrable domain, e.g. 'example.com'.
rpName
> rpName: string
Defined in: auth/src/webauthn.ts:276
Human-readable RP name shown in the OS prompt.
timeoutMs?
> optional timeoutMs?: number
Defined in: auth/src/webauthn.ts:289
Ceremony timeout advertised to the browser, ms. Default 60s.
userVerification?
> optional userVerification?: "required" | "preferred" | "discouraged"
Defined in: auth/src/webauthn.ts:287
User-verification requirement. Default 'preferred' (the WebAuthn default): an authenticator without a PIN/biometric can still sign, so the assertion proves possession only. Set 'required' when a passkey is the ONLY factor (passwordless login) and you need two factors in one gesture.