[webauthn] Re-Open "confirmation" discussion (see PR#2020) (#2352)

rlin1 has just created a new issue for https://github.com/w3c/webauthn:

== Re-Open "confirmation" discussion (see PR#2020) ==
I was asked by the FIDO2 working group, to re-open the transaction confirmation discussion in WebAuthn WG.

## Description

Ability for relying parties to pass a confirmation prompt to the authenticator (e.g., security key with a display) through official "rails" - as opposed to using other protocol elements that were introduced for other purposes.
Ability for the authenticator to cryptographically link the confirmation prompt to the generated assertion - if the authenticator has shown it.
Ability for the client (e.g., Browser) to display the confirmation prompt on behalf of the authenticator (e.g., security key without a display). Ability for the client to include the confirmation prompt that was shown in the clientDataJSON.

## Related Links
See https://github.com/w3c/webauthn/pull/2020 as a starting point.

Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2352 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 28 October 2025 15:29:29 UTC