Skip to content

basalt / auth/src / WebAuthnConfig

Interface: WebAuthnConfig ​

Defined in: auth/src/webauthn.ts:272

Properties ​

challengeTtlMs? ​

> optional challengeTtlMs?: number

Defined in: auth/src/webauthn.ts:280

Challenge TTL in ms. Default 5 minutes.


origin ​

> origin: string | string[]

Defined in: auth/src/webauthn.ts:278

Expected origin(s), e.g. 'https://example.com'.


pubKeyCredParams? ​

> optional pubKeyCredParams?: PublicKeyParam[]

Defined in: auth/src/webauthn.ts:291

Override the accepted algorithms. Default ES256 + RS256.


rpId ​

> rpId: string

Defined in: auth/src/webauthn.ts:274

Relying Party ID — your registrable domain, e.g. 'example.com'.


rpName ​

> rpName: string

Defined in: auth/src/webauthn.ts:276

Human-readable RP name shown in the OS prompt.


timeoutMs? ​

> optional timeoutMs?: number

Defined in: auth/src/webauthn.ts:289

Ceremony timeout advertised to the browser, ms. Default 60s.


userVerification? ​

> optional userVerification?: "required" | "preferred" | "discouraged"

Defined in: auth/src/webauthn.ts:287

User-verification requirement. Default 'preferred' (the WebAuthn default): an authenticator without a PIN/biometric can still sign, so the assertion proves possession only. Set 'required' when a passkey is the ONLY factor (passwordless login) and you need two factors in one gesture.

Released under the MIT License.