Based on the WebAuthn specification, a Passkey is a discoverable public key cryptographic credential that provides a flexible passwordless experience across multiple devices.

Hi, I’m Peter Fernandez, and as a CIAM expert, I want to share my experience building Passkey authentication into modern applications.

Discoverable

Passkeys are primarily discoverable FIDO credentials. Discoverable credentials are a mechanism provided by the WebAuthn specification that allows for seamless authentication without the user having to provide either a username or password, irrespective of the device being used.

Device Bound

Passkeys can also be device-bound. Device-bound passkeys — also known as single-device passkeys — are FIDO authentication credentials unique to the device they’re created on. A device-bound passkey is typically stored on a physical security key or device, rather than being discoverable (via the cloud).

Build vs Buy vs DIY

You could build an in-house custom solution yourself…it’s certainly an option. Particularly if you have a team with the time, capacity, knowledge, and expertise to develop:

  • SSO,
  • Leverage OIDC and/or SAML for Authentication, Social and/or (Enterprise) Federation,
  • Implement Passwordless, Passkeys and/or MFA, with optional
  • OAuth 2.0 for API Authorization, as well as
  • Deploy and maintain Attack Protection.

The alternative is to integrate with a SaaS solution provided by one of the popular vendors, and the cost of subscribing to one of these typically depends on the features you use and the number of active consumer identities you have.

With vendor-based CIAM, the cost is typically associated with the platform hosting the backend service(s) that deliver Authentication, Authorization, Management and Protection from attack.

With consumer-oriented SaaS, much of this infrastructure is already in place: cloud-based “compute”, database, network resources, etc., could be a necessity for your solution, and delivering these at scale may be something you also need to do.

Deploying a standards-based (open-source) DIY solution within your existing infrastructure might provide a more cost-effective approach, delivering secure and robust CIAM without the need to build everything yourself and with the added benefit of more flexibility and control.

Questions? Comments?
Feel free to reach out!