navigator.credentials. Either way you get standard WebAuthn JSON to send to your server.
The relying party is always cskn.app, so a passkey created in the mobile app also works when the user opens the same app in a browser.
API
transport is native (the shell runs the ceremony), web (the page’s own WebAuthn) or none.
create options
string
required
Base64url challenge from your server.
{ id?, name?, displayName? }
In the mobile shell, the user handle is always the signed-in user’s
sub.PasskeyCredentialDescriptor[]
Credentials the user already has.
object
Standard WebAuthn selection, for example
{ userVerification: 'required' }.…
Standard WebAuthn options.
get options
string
required
Base64url challenge from your server.
PasskeyCredentialDescriptor[]
Omit for discoverable sign-in.
'discouraged' | 'preferred' | 'required'
Standard WebAuthn option.
Details
- Binary fields are base64url. Convert with
base64UrlFromBytes(bytes)andbytesFromBase64Url(text). response.publicKeyfromcreateis always DER SubjectPublicKeyInfo, the same as a browser’sgetPublicKey(). The shell normalizes the platform differences.- Error codes:
not_supported,not_configured,no_credentials,rp_not_allowed,invalid_request,interrupted,failed. - TV has no passkeys (
transport: 'none').
isPasskeyAvailable, createPasskey, getPasskey.