Appearance
Passkeys
Passkeys provide WebAuthn user presence and, where available, PRF-derived holder-side material.
Role In The Model
Passkeys can:
- prove local user presence;
- derive or unlock holder-side material;
- step up expired or exhausted Wallet Session quotas;
- authorize sensitive operations when policy requires a cryptographic factor.
Passkeys do not make app sessions into signing authority. Passkey results are normalized into the same lane, Wallet Session/quota, capability-grant, and policy model as other auth methods.