New: Passkey Benchmark 2026 · compare your rollout

Passkeys Debugger & WebAuthn Tester

Test passkeys, parse WebAuthn responses and debug attestation and assertion, free in your browser. Run real registration and login ceremonies with your own server options, inspect AAGUIDs, COSE keys and client capabilities, and reproduce Chrome, Safari and Android passkey failures.

1,730 community sessions across 108 authenticators. See live stats

Checked live in your browser

Detecting your browser…

Checking…

WebAuthn Debugger — paste a response, get parsed JSON

Pick the passkey operation you want to test, customize the server options (user verification, attestation, transports), or paste a registration / authentication response to inspect attestation, AAGUID, COSE public key, and client capabilities.

Request

The options your server sends to the browser. Change them below or edit the JSON directly.

navigator.credentials.create(…)
Editable

Response

What the authenticator returned. You can also paste a registration response from your own app to decode it.

Raw JSON
Editable
Decoded

Decoded fields (attestation object, AAGUID, public key) appear here once there's a response.

Your Browser & OS Information

Below you'll find detailed information about your browser, operating system, and support for passkeys and related WebAuthn features.

Compare with the field: Web Passkey Readiness·WebAuthn Client Capabilities·Provider Market Share

Parsed User Agent
Parsed Client Hints

What the community is testing in October 2026

A live snapshot of the authenticators, platforms, and credential types other developers are putting through this debugger.

Top authenticators

Not enough data yet.

Requested → returned attachment

Not enough data yet.

Requested → returned user verification

Not enough data yet.

Top operating systems

Not enough data yet.

Top browsers

Not enough data yet.

Transport combos

Not enough data yet.

Credential backup

Not enough data yet.

Public key algorithm

Not enough data yet.

Ceremony type

Not enough data yet.

How this compares in the field

The debugger shows what one ceremony does. The Passkey Benchmark 2026 aggregates production traffic from large-scale Corbado deployments — handy when you need to know whether the value you just parsed is normal or an outlier.

Frequently asked questions

Common debugging questions developers ask before reaching for the Passkeys Debugger.

How do I debug a WebAuthn registration response?

Run a registration ceremony in the debugger or paste an existing attestation response into the response inspector. The Passkeys Debugger decodes the CBOR-encoded attestationObject, extracts authData (rpIdHash, flags, signCount, attestedCredentialData), decodes the credentialPublicKey from its COSE_Key encoding, and pulls the AAGUID — then shows the requested vs. returned user verification, attachment and transports so you can see where the authenticator diverged from your server options.

Try registration in the debugger →

How do I test generateRegistrationOptions end-to-end?

The debugger accepts the same inputs @simplewebauthn/server's generateRegistrationOptions takes — rpName, rpID, userName, userID, userDisplayName, challenge, timeout, attestationType, excludeCredentials, authenticatorSelection (residentKey, userVerification, authenticatorAttachment), extensions, and supportedAlgorithmIDs — then runs a real registration in your browser. You see the full PublicKeyCredentialCreationOptions object passed to navigator.credentials.create() and the full parsed response, so you can validate every flag end-to-end without writing a server.

Configure options →

Can I paste a passkey authentication response and parse it?

Yes. Use the response inspector to paste an authentication assertion (clientDataJSON, authenticatorData, signature, userHandle). The debugger decodes the authData flag byte (UP, UV, BE, BS, plus AT and ED), the RP ID hash, the signature counter, and any authenticator extension outputs (the CBOR map at the end of authData) — client extension results from getClientExtensionResults() are surfaced separately. The clientDataJSON challenge is decoded so you can confirm it matches the one you sent.

Open the debugger →

How do I reproduce a Chrome passkey failure (NotAllowedError)?

Pick the registration or login flow, set the exact options your production server sends, and run it in the affected browser. Common Chrome failure modes: residentKey: "required" with a security key that doesn't support resident credentials, and userVerification: "required" on an authenticator without UV capability. With attestation: "direct", Chrome shows a user-consent prompt for cross-platform security keys (denial fails the call), while platform authenticators return a privacy-preserving none-equivalent attestation by design — including iCloud Keychain, which intentionally emits an all-zero AAGUID. The parsed response shows which options were honored.

How-to: test a platform authenticator →

How do I test Bluetooth or hybrid transport on Android?

Open the debugger on the device under test (or use a Remote Test link to drive a phone from your laptop). The valid AuthenticatorTransport values are usb, nfc, ble, smart-card, hybrid, and internal. In practice, cross-device QR-code passkey flows use hybrid (formerly known as caBLE) — pure ble is rarely advertised by today's consumer authenticators. The parsed response shows the transports the authenticator actually returned, so you can confirm whether hybrid or another transport was used end-to-end.

How-to: test a security key →

What does an AAGUID identify?

The AAGUID is a 128-bit identifier in the attestedCredentialData of authData that names the authenticator make and model — e.g. Google Password Manager, 1Password, YubiKey 5 NFC. Consumer iCloud Keychain intentionally emits an all-zero AAGUID for privacy, so it cannot be identified by AAGUID alone (only the MDM-managed variant emits a non-zero value). The debugger extracts the AAGUID on every registration and resolves it to a human name and icon using the community AAGUID map. Click any AAGUID to copy it.

See top authenticators →

Enterprise passkey products

Observe passkey failures or let Corbado run passkeys

  • Keep your existing IDP
  • Per-user passkey journey visibility
  • Device and authenticator readiness
  • Support and rollout reporting