Pular para o conteúdo principal

Set up WebAuthn sign-in

This guide explains how to turn on WebAuthn sign-in. Users then sign in with an authenticator that is built in to their device, such as a fingerprint reader, face recognition, or Windows Hello, or with a security key such as a YubiKey, instead of or in addition to a password.


Learning outcomes​

  • Configure Casdoor for WebAuthn.
  • Offer WebAuthn as a sign-in method of an application.
  • Register a WebAuthn credential for a user.

What you need​

  • Access to conf/app.conf of your Casdoor instance
  • Casdoor served over HTTPS. WebAuthn requires HTTPS, except on localhost.
  • A device with a WebAuthn authenticator

About WebAuthn​

Web Authentication (WebAuthn) is a standard of the W3C and the FIDO Alliance that signs users in with public-key cryptography. Casdoor stores a public key. The private key never leaves the device of the user. To sign in, the user proves possession of the private key, typically with a biometric check or a security key. A credential is bound to the user, the authenticator, and the origin of the site.

For an introduction, see webauthn.guide.

Configure Casdoor​

  1. In conf/app.conf, set origin to the exact URL under which users open Casdoor:

    origin = "http://localhost:8000"
  2. Restart Casdoor.

Add WebAuthn to the sign-in methods​

  1. In the Casdoor admin console, go to Identity > Applications and open the application.
  2. In Signin methods, add WebAuthn.
  3. Save the application.

Register a credential​

Each user registers their own credential:

  1. Sign in and open My Account.

  2. In WebAuthn credentials, add a credential and follow the prompt of your device.

    WebAuthn credentials on the account page

To remove a credential, delete it from the same list.

Verify the result​

  1. Sign out.

  2. On the sign-in page, select the WebAuthn method.

  3. Enter your username and click Sign in with WebAuthn.

  4. Complete the prompt of your authenticator, for example with your fingerprint or Windows Hello.

    Sign-in page with the WebAuthn method

See also​