Re: [webauthn] Add onlyCreate to prevent creation of a new key for existing user (#2313)

Since discussion around this is a bit fragmented (#1533, #2309, #1749, #2313, #1568, etc.), a question to the maintainers: is there any "canonical" place where developers like me can vote for the fundamental use case being discussed in all of these threads (i.e. "Having an app with one button "Sign-in with passkey". If user does not have an account with their device, one is created for them. If they do have, they are signed-in. No username, no user ID.")?

(if there isn't a good existing thread, would it be useful to create one? Or would that just add to the existing noise?)

Personally I don't really care what the specific implementation details are, but I'd like the _capability_ to hopefully be discussed for whatever the next milestone is after L4 (because as mentioned in the previous comment, it's already rejected for L4)

-- 
GitHub Notification of comment by davidje13
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2313#issuecomment-3246502512 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 2 September 2025 19:14:59 UTC