Re: [webauthn] Headless API (#1924)

You aren't meant to use webauthn in those cases. A human logs in with webauthn, gets a bearer token / cookie, then the browser uses that for interactions.

For scripting and server-to-server this also isn't a webauthn use case, this is for TPM's or other security primitives. 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1924#issuecomment-1641193555 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 19 July 2023 00:24:00 UTC