# Passkeys

Passkeys are a passwordless authentication technology involving client authentication assertions, server-side challenges, credential options, and cryptographic verification.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## UK.gov begins killing off passwords for 23 million users

DevFeed: [UK.gov begins killing off passwords for 23 million users](<https://devfeed.tech/articles/uk-gov-begins-killing-off-passwords-for-23-million-users-17411.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088>)

Author: Carly Page

Published: 2026-09-14T09:16:11Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [government-of-the-united-kingdom](<https://devfeed.tech/tags/government-of-the-united-kingdom.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [uk](<https://devfeed.tech/tags/uk.md>), [whitehall](<https://devfeed.tech/tags/whitehall.md>)

### AI overview

The UK government is beginning to replace passwords with passkeys for 23 million users. The change is intended to reduce phishing problems and save Whitehall approximately GBP 600 per day in SMS costs.

### Source excerpt

Passkeys promise fewer phishing headaches - and GBP 600 a day off Whitehall's SMS bill

## AuthKit vs Better Auth for B2B SaaS

DevFeed: [AuthKit vs Better Auth for B2B SaaS](<https://devfeed.tech/articles/authkit-vs-better-auth-for-b2b-saas-17462.md>)

Original publisher: [Read original article](<https://workos.com/blog/authkit-vs-better-auth-b2b>)

Author: WorkOS

Published: 2026-09-14T00:00:00Z

Content type: comparison

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Frameworks](<https://devfeed.tech/topics/frameworks.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [logs](<https://devfeed.tech/tags/logs.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

This comparison examines AuthKit and Better Auth as platforms for B2B SaaS products selling to enterprise IT buyers. It argues that both now provide core capabilities such as SSO, SCIM, and audit logs, so the meaningful differences are provider coverage, where user lifecycle management begins, and contractual responsibility. The article also describes Better Auth's hosted infrastructure, dashboard, SIEM drain, self-service provisioning, and threat detection features, while noting its convergence with AuthKit on enterprise requirements.

### Source excerpt

Both ship SSO, SCIM and audit logs now. The comparison that decides enterprise deals has moved to the long tail: provider coverage, where user lifecycle actually starts, and who is contractually on the hook.

## How WhatsApp Implemented Passkey Authentication for Faster, Phishing-Resistant Sign-In

DevFeed: [How WhatsApp Implemented Passkey Authentication for Faster, Phishing-Resistant Sign-In](<https://devfeed.tech/articles/how-whatsapp-upgraded-to-secure-seamless-sign-in-for-1-billion-users-with-passkeys-22699.md>)

Original publisher: [Read original article](<http://android-developers.googleblog.com/2026/08/whatsapp-passkeys-secure-sign-in.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-27T17:00:00Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-3.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Android](<https://devfeed.tech/topics/android.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [developer](<https://devfeed.tech/tags/developer.md>), [google](<https://devfeed.tech/tags/google.md>), [meta](<https://devfeed.tech/tags/meta.md>), [sign-in](<https://devfeed.tech/tags/sign-in.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

The article describes how WhatsApp implemented passkey-based authentication to provide faster sign-ins and reduce phishing and credential-theft risks. It explains the use of public-private key cryptography, biometric or screen-lock authentication, and Android's Credential Manager API.

### Source excerpt

Posted by Niharika Arora, Senior Developer Relations Engineer, Tracy Agyemang, Product Marketing Manager, Google and Mayank Manuja, Android Engineer, Meta WhatsApp is the world's largest messaging platform, serving billions of users globally. It is the default communication tool for people across diverse regions, connecting users through private, reliable, and secure messaging. "What excites me most is the sheer scale of WhatsApp's impact. Even a small improvement to WhatsApp touches billions of users worldwide," says Mayank Manuja, an Android Engineer on the WhatsApp Registration and Access team who led the design and implementation of passkey-based authentication for WhatsApp. Building for an audience of this magnitude requires navigating a vast range of network conditions, device capabilities, and levels of digital literacy. Recognizing the potential early, WhatsApp committed to adopting passkeys in 2023, becoming one of the first major consumer apps to integrate the technology. By implementing passkeys, WhatsApp aimed to provide a fast, phishing-resistant option that significantly reduces user friction while providing robust protection against account takeovers and credential theft. A user creating a passkey on WhatsApp for faster, more secure sign-ins. The Decision to Adopt Passkeys For WhatsApp, offering multiple access methods is key to making it easier for users to stay connected and regain access when needed. Passkeys offer users a streamlined, one-tap login experience that eliminates phishing risks and functions reliably even in regions where OTP message delivery can be inconsistent. Underneath, passkeys leverage public-private key cryptography to replace manual entry with biometric or screen lock authentication. This workflow drastically improves sign-in speeds by reducing the process to a single tap via a unified, bottom-sheet interface that keeps users engaged within the app's context. The benefits are twofold: passkeys offer users a streamlined login e

## How WhatsApp Upgraded to Secure, Seamless Sign-In for 1 Billion Users with Passkeys

DevFeed: [How WhatsApp Upgraded to Secure, Seamless Sign-In for 1 Billion Users with Passkeys](<https://devfeed.tech/articles/how-whatsapp-upgraded-to-secure-seamless-sign-in-for-1-billion-users-with-passkeys-4242.md>)

Original publisher: [Read original article](<https://android-developers.googleblog.com/2026/08/whatsapp-passkeys-secure-sign-in.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-27T17:00:00Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog.md>), [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-2.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Android](<https://devfeed.tech/topics/android.md>), [App](<https://devfeed.tech/topics/app.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [api](<https://devfeed.tech/tags/api.md>), [app](<https://devfeed.tech/tags/app.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scale](<https://devfeed.tech/tags/scale.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

WhatsApp's adoption of passkeys provides a fast, phishing-resistant sign-in method for its large global user base. The article explains how passkeys use public-private key cryptography with biometric or screen-lock authentication, reduce reliance on inconsistent SMS OTP delivery, and simplify implementation through Android's Credential Manager API.

### Source excerpt

Posted by Niharika Arora, Senior Developer Relations Engineer, Tracy Agyemang, Product Marketing Manager, Google and Mayank Manuja, Android Engineer, Meta WhatsApp is the world's largest messaging platform, serving billions of users globally. It is the default communication tool for people across diverse regions, connecting users through private, reliable, and secure messaging. "What excites me most is the sheer scale of WhatsApp's impact. Even a small improvement to WhatsApp touches billions of users worldwide," says Mayank Manuja, an Android Engineer on the WhatsApp Registration and Access team who led the design and implementation of passkey-based authentication for WhatsApp. Building for an audience of this magnitude requires navigating a vast range of network conditions, device capabilities, and levels of digital literacy. Recognizing the potential early, WhatsApp committed to adopting passkeys in 2023, becoming one of the first major consumer apps to integrate the technology. By implementing passkeys, WhatsApp aimed to provide a fast, phishing-resistant option that significantly reduces user friction while providing robust protection against account takeovers and credential theft. A user creating a passkey on WhatsApp for faster, more secure sign-ins. The Decision to Adopt Passkeys For WhatsApp, offering multiple access methods is key to making it easier for users to stay connected and regain access when needed. Passkeys offer users a streamlined, one-tap login experience that eliminates phishing risks and functions reliably even in regions where OTP message delivery can be inconsistent. Underneath, passkeys leverage public-private key cryptography to replace manual entry with biometric or screen lock authentication. This workflow drastically improves sign-in speeds by reducing the process to a single tap via a unified, bottom-sheet interface that keeps users engaged within the app's context. The benefits are twofold: passkeys offer users a streamlined login e

## 1Password product enhancements: Smarter autofill, phishing prevention, and more

DevFeed: [1Password product enhancements: Smarter autofill, phishing prevention, and more](<https://devfeed.tech/articles/1password-product-enhancements-smarter-autofill-phishing-prevention-and-more-1884.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-product-enhancements-smarter-autofill-phishing-prevention>)

Author: info@1password.com (Elaine Atwell)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [macos](<https://devfeed.tech/tags/macos.md>), [migration](<https://devfeed.tech/tags/migration.md>), [news](<https://devfeed.tech/tags/news.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [product](<https://devfeed.tech/tags/product.md>), [saas](<https://devfeed.tech/tags/saas.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This English developer article presents recent 1Password product enhancements focused on smoother credential management and sign-in. It covers universal sign-in for personal and business accounts, macOS autofill, native password generation and saving in iOS 26.2, an iOS autofill health check, and improvements related to data ownership and migration.

### Source excerpt

At 1Password, we're constantly working to make life simpler and more secure for our users, from the biggest businesses to each individual who signs up for our password manager. Over the past few months, we've been rolling out a slew of updates designed to make a difference for customers, whether you're using us at home, at work, or (ideally) both. Here are some of the latest developments for you to explore. Upgrades to autofill and autosave One of the most immediate benefits of using 1Password in your daily life is a smooth experience of creating, saving, and inputting your credentials and logins. These updates help you get the most out of that experience, with fewer clicks, on the devices you already use. Universal sign-in for personal and business accounts Signing in just got simpler with a smarter, modern experience using a one-click prompt. Now in beta, 1Password seamlessly logs you into any site or service at the right moment using your desired authentication method (passwords, passkeys, social sign in, OIDC, SAML*). We remove all the extra steps so you sign in quickly and smoothly, while staying secure. *SAML is only available for business accounts that also have 1Password SaaS Manager. macOS autofill 1Password now works as a native Credential Provider on macOS, so your logins and passkeys easily fill right inside Safari and other desktop apps. Save and generate passwords in iOS 26.2 The password creation experience on iPhone and iPad should happen at the exact moment you need it, especially when you're signing up for a new account. With this update, 1Password shows up natively in Safari and other iOS-native apps so you can generate and save a strong password right in the account creation flow, without leaving what you're doing. This makes it easier to capture credentials when they're created and keeps account setup uninterrupted. Autofill health check for iOS The reliability of iOS autofill depends on a tangle of systems, and when there's a problem with one,

## Roadmap decisions rather than dates.

DevFeed: [Roadmap decisions rather than dates.](<https://devfeed.tech/articles/roadmap-decisions-rather-than-dates-35683.md>)

Original publisher: [Read original article](<https://lethain.com/decisions-not-dates/>)

Published: 2026-08-11T14:00:00Z

Content type: opinion

Language: en

Sources: [Will Larson - Irrational Exuberance](<https://devfeed.tech/sources/will-larson-irrational-exuberance.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [resiliency](<https://devfeed.tech/topics/resiliency.md>), [User Experience](<https://devfeed.tech/topics/user-experience.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [development](<https://devfeed.tech/tags/development.md>), [experience](<https://devfeed.tech/tags/experience.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [resiliency](<https://devfeed.tech/tags/resiliency.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

The article argues that product roadmaps should prioritize decisions and execution constraints rather than fixed dates. It uses the development and rollout of passkey support at Imprint as an example, describing implementation behind a feature flag, staged web release, feedback iteration, and expansion to native mobile experiences.

### Source excerpt

One thing that bothered me about Imprint's product after joining was our lack of passkey support. Passkey support is a rare opportunity to increase resiliency to phishing attacks while simultaneously reducing login friction. If it's good for our members, our partners, and our product, it felt like something we should have already shipped. Nonetheless, it was hard to get it onto the roadmap alongside everything else we were working on. To dig into passkeys, I started sketching out the implementation as a side quest. Some iterations later, I had something implemented behind a disabled feature flag for team review. At that point, most problems had a concrete solution implemented, and the remaining issues were messy intersections between passkey implementation and user experience. Issues remained, but the tangible implementation made tradeoffs explicit, and we were able to work through them. Soon thereafter, we launched passkeys to a small group in our web experience, iterated on feedback, finalized the details, and brought those details forward to our native mobile experiences as well. It never got onto the roadmap, but it did ship. Our passkey release planted a seed for me, but it required another experience to fully germinate. We had a discussion about hitting a date for a product extension we're developing. Our conversation kept anchoring on the idea that pulling in a date was dependent on pushing out dates for other projects. Presenting two conflicting projects as requiring timeline tradeoffs wouldn't have caused me to blink an eye five years ago, but in this conversation it inspired a sort of instinctual revolt: with modern development techniques, I believe very few projects are essentially constrained by execution bandwidth. Some are constrained by approvals, others are constrained by cross-team and cross-functional handoffs, and many are constrained by missing decisions, but almost none should be constrained purely on time. Shifting blocks of time across project

## Passkeys in B2B: the real risk is recovery

DevFeed: [Passkeys in B2B: the real risk is recovery](<https://devfeed.tech/articles/passkeys-in-b2b-the-real-risk-is-recovery-16042.md>)

Original publisher: [Read original article](<https://workos.com/blog/passkeys-consumer-advice-breaks-in-enterprise>)

Author: WorkOS

Published: 2026-08-06T15:29:33Z

Content type: article

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [b2b](<https://devfeed.tech/tags/b2b.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [recovery](<https://devfeed.tech/tags/recovery.md>)

### AI overview

The article explains why consumer passkey guidance does not fully apply to B2B systems. Although passkeys are phishing-resistant WebAuthn credentials, synced passkeys may reside in employees' personal cloud accounts, creating enrollment, ownership, recovery, and revocation challenges when devices are lost or employees leave.

### Source excerpt

Consumer passkey guidance optimizes for the login. In B2B, the enrollment and recovery story is what decides whether passkeys actually work. Here's the gap.

## Opaque, Interoperable Passkey Records (and a Go API)

DevFeed: [Opaque, Interoperable Passkey Records (and a Go API)](<https://devfeed.tech/articles/opaque-interoperable-passkey-records-and-a-go-api-20699.md>)

Original publisher: [Read original article](<https://words.filippo.io/passkey-record/>)

Author: Filippo Valsorda

Published: 2026-07-20T22:33:32Z

Content type: article

Language: en

Sources: [Filippo Valsorda](<https://devfeed.tech/sources/filippo-valsorda.md>)

Topics: [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [go](<https://devfeed.tech/tags/go.md>), [password](<https://devfeed.tech/tags/password.md>), [security](<https://devfeed.tech/tags/security.md>), [web](<https://devfeed.tech/tags/web.md>), [web-developers](<https://devfeed.tech/tags/web-developers.md>)

### AI overview

The article proposes interoperable passkey record encodings for WebAuthn credentials, allowing applications to store records as opaque strings similar to password hashes. It also presents a potential Go API for handling these records.

### Source excerpt

Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.

## Sign in to Pulumi Cloud with Passkeys

DevFeed: [Sign in to Pulumi Cloud with Passkeys](<https://devfeed.tech/articles/sign-in-to-pulumi-cloud-with-passkeys-19019.md>)

Original publisher: [Read original article](<https://www.pulumi.com/blog/passkey-support-in-pulumi-cloud/>)

Author: Devon Grove

Published: 2026-07-13T00:00:00Z

Content type: release

Language: en

Sources: [Pulumi](<https://devfeed.tech/sources/pulumi.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [bitbucket](<https://devfeed.tech/tags/bitbucket.md>), [features](<https://devfeed.tech/tags/features.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [google](<https://devfeed.tech/tags/google.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [product](<https://devfeed.tech/tags/product.md>), [product-launches](<https://devfeed.tech/tags/product-launches.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Pulumi Cloud now supports passkeys for users who sign in with an email address and password. Passkeys use device-stored public-key credentials and WebAuthn, while identity-provider sign-in flows remain unchanged.

### Source excerpt

Pulumi Cloud now supports passkeys for users who sign in with email and password. Select a button, approve with Touch ID, Face ID, Windows Hello, or your hardware key, and you're signed in. A passkey is a public-key credential stored on your device: your phone, your laptop, a hardware key (YubiKey, Google Titan, etc.), or your password manager can all function as the authenticator. When you sign in, your device authenticates you locally and signs a challenge from Pulumi Cloud with the private key. The private key stays on your device -- Pulumi Cloud never sees or stores it. Passkeys are built on the WebAuthn standard, so they're already supported on every major browser and operating system. Who this is for This release applies to users who sign in to Pulumi Cloud with an email address and password. If you sign in through an identity provider (IdP), such as GitHub OAuth, GitLab, Bitbucket, Google, or your organization's SAML SSO, your existing flow is unchanged. Why passkeys Passwords have always been the weakest link in account security. Since they are shared secrets, they are vulnerable to phishing attacks, and every place you type one is a place that can be impersonated or a data store that can be leaked. Passkeys swap that out for a per-site key pair that lives on your device: Phishing-resistant by design. A passkey is bound to the exact origin it was registered for. A look-alike domain can't trigger your authenticator. Synced across your devices. Apple iCloud Keychain, Google Password Manager, 1Password, Dashlane, Bitwarden: most credential managers now sync passkeys end-to-end-encrypted to every device you've signed in on. Discoverable. Pulumi Cloud doesn't need to know which user you are before you authenticate. Just select "Sign in with a passkey" and your device offers the right credential. Nothing to remember. A passkey lives on your device. There's no string to memorize, and no sensitive credential stored by us. Setting up a passkey The next time you sign i

## AI, OAuth, And Other Platform APIs In The Core

DevFeed: [AI, OAuth, And Other Platform APIs In The Core](<https://devfeed.tech/articles/ai-oauth-and-other-platform-apis-in-the-core-19436.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/platform-apis-in-the-core/>)

Author: Shai Almog

Published: 2026-05-31T00:00:00Z

Content type: article

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [API](<https://devfeed.tech/topics/api.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Ollama](<https://devfeed.tech/topics/ollama.md>), [llama.cpp](<https://devfeed.tech/topics/llama-cpp.md>), [vllm](<https://devfeed.tech/topics/vllm.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>)

Tags: [agent-skill](<https://devfeed.tech/tags/agent-skill.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [function-calling](<https://devfeed.tech/tags/function-calling.md>), [llama-cpp](<https://devfeed.tech/tags/llama-cpp.md>), [llm](<https://devfeed.tech/tags/llm.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [ollama](<https://devfeed.tech/tags/ollama.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [vllm](<https://devfeed.tech/tags/vllm.md>)

### AI overview

This follow-up release article describes platform APIs moved into the framework core, including a first-class LLM client and ChatView, OAuth and OIDC authentication, WebAuthn passkeys, WiFi and connectivity APIs, and share-sheet callbacks. It also outlines streaming chat, tool calls, embeddings, image generation, and local-model support through Ollama-compatible endpoints.

### Source excerpt

Deeper AI integration in the framework core, modern authentication via OAuth / OIDC and WebAuthn passkeys driven from the system browser, and a few smaller additions alongside.

## Passkeys: How They Address Password Defects and Their Limitations

DevFeed: [Passkeys: How They Address Password Defects and Their Limitations](<https://devfeed.tech/articles/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now-38397.md>)

Original publisher: [Read original article](<https://blog.danlew.net/2026/05/21/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now/>)

Author: Dan Lew

Published: 2026-05-21T13:29:09Z

Content type: tutorial

Language: en

Sources: [Dan Lew Blog](<https://devfeed.tech/sources/dan-lew-blog.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [talk](<https://devfeed.tech/tags/talk.md>)

### AI overview

A writeup of a Minnebar 20 talk explaining passkeys in the context of password history. It distinguishes authentication from authorization and examines password deficiencies, how passkeys address them, and passkeys' own problems.

### Source excerpt

This is a writeup of a talk I gave at Minnebar 20. Originally, I threw in some Matrix references to make the talk more fun & engaging. Those jokes work better in person, so I've mostly omitted the Matrix from this writeup (though some vestiges remain). It seems

## Import, autofill, organize: What's new in 1Password this quarter

DevFeed: [Import, autofill, organize: What's new in 1Password this quarter](<https://devfeed.tech/articles/import-autofill-organize-what-s-new-in-1password-this-quarter-1931.md>)

Original publisher: [Read original article](<https://1password.com/blog/import-autofill-organize-whats-new-in-1password-this-quarter>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-05-05T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Android](<https://devfeed.tech/topics/android.md>), [iOS](<https://devfeed.tech/topics/ios.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [ios](<https://devfeed.tech/tags/ios.md>), [migration](<https://devfeed.tech/tags/migration.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [release](<https://devfeed.tech/tags/release.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

1Password's latest release adds direct credential transfer through the Credential Exchange Protocol, Android Autofill health checks, and improved login item creation. The updates aim to simplify migration, mobile setup, and everyday password management.

### Source excerpt

A password manager should make everyday tasks feel simple. Whether that's: Saving a new password Signing in on your phone Finding the right item Moving your data from another password manager We've made a set of updates across 1Password in our latest release to improve exactly these moments. Let's get into it! A direct way to move your credentials into 1Password Switching password managers hasn't always felt straightforward. Exporting sensitive data into files, moving them yourself, and importing them again adds friction and risk. We're improving that with a direct credential transfer. This work is part of the Credential Exchange Protocol (CXP), an industry effort to make credential migration more secure and interoperable. We helped author the FIDO Alliance's Credential Exchange Format (CXF), a proposed standard that defines how credentials like passwords, passkeys, and other sensitive data can be structured and transferred safely between providers. For you, this means a simpler experience on both iOS and Android, letting you move your credentials into 1Password without relying on manual export and import, and eliminating the need to handle sensitive files yourself. Get your Autofill setup working smoothly on Android Currently, Autofill on Android depends on several system settings, and when something isn't configured correctly, it's not always clear what the problem is or how to fix it. So we've made this easier. 1Password now brings those settings into one place and checks them for you. You can see at a glance if something isn't set up correctly, like Autofill not being enabled, the wrong service selected, or a required permission turned off. For each issue, 1Password explains what's wrong and takes you directly to the right Android setting so you can fix it. You can also see a simple summary of your setup, so you know whether everything is working as expected or if something needs attention. All of this can be found on the home screen of 1Password by navigating t

## Introducing Advanced Account Security

DevFeed: [Introducing Advanced Account Security](<https://devfeed.tech/articles/introducing-advanced-account-security-6273.md>)

Original publisher: [Read original article](<https://openai.com/index/advanced-account-security>)

Published: 2026-04-30T00:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [codex](<https://devfeed.tech/topics/codex.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [codex](<https://devfeed.tech/tags/codex.md>), [data](<https://devfeed.tech/tags/data.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [product](<https://devfeed.tech/tags/product.md>), [recovery](<https://devfeed.tech/tags/recovery.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

OpenAI introduces Advanced Account Security, an opt-in setting for ChatGPT accounts that also protects Codex through the same login. It combines stronger sign-in requirements, tighter account recovery, reduced exposure from compromised sessions, and greater visibility into account activity. The setting requires passkeys or physical security keys, disables password-based login and email or SMS recovery, and supports backup passkeys, security keys, and recovery keys.

### Source excerpt

Introducing Advanced Account Security: phishing-resistant login, stronger recovery, and enhanced protections to safeguard sensitive data and prevent account takeover.

## How Multi-Factor Authentication Helps Keep Your Discord Account Safe

DevFeed: [How Multi-Factor Authentication Helps Keep Your Discord Account Safe](<https://devfeed.tech/articles/how-multi-factor-authentication-helps-keep-your-discord-account-safe-260.md>)

Original publisher: [Read original article](<https://discord.com/blog/keeping-discord-safe-and-sound>)

Author: Locke

Published: 2026-03-27T00:00:00Z

Content type: tutorial

Language: en

Sources: [Discord Blog](<https://devfeed.tech/sources/discord-blog.md>)

Topics: [MFA](<https://devfeed.tech/topics/mfa.md>), [Discord](<https://devfeed.tech/topics/discord.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Security](<https://devfeed.tech/topics/security.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [blog](<https://devfeed.tech/tags/blog.md>), [discord](<https://devfeed.tech/tags/discord.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This Discord blog post explains how multi-factor authentication, passkeys, authenticator apps, SMS backup authentication, and QR code login can help protect Discord accounts from account takeover.

### Source excerpt

A Discord account is more than just your username and avatar. That's why it's important to help keep your account safe and secure by using Multi-Factor Authentication, SMS Backup Authentication & QR Code Login. Learn how to keep your account more secure in the following blog post!

## Keycloak 26.4.0 released

DevFeed: [Keycloak 26.4.0 released](<https://devfeed.tech/articles/keycloak-26-4-0-released-31723.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/09/keycloak-2640-released>)

Author: Keycloak Team

Published: 2025-09-30T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Security](<https://devfeed.tech/topics/security.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Specifications](<https://devfeed.tech/topics/specifications.md>), [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [oauth-2-0](<https://devfeed.tech/tags/oauth-2-0.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [specifications](<https://devfeed.tech/tags/specifications.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>), [sso](<https://devfeed.tech/tags/sso.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Keycloak 26.4.0 introduces passkeys, federated client authentication using SPIFFE or Kubernetes service account tokens, support for final FAPI 2.0 specifications, and full DPoP support. The release also includes availability and administration improvements.

### Source excerpt

To download the release go to Keycloak downloads. Highlights This release features new capabilities focused on security enhancements, deeper integration, and improved server administration. The highlights of this release are: Passkeys for seamless, passwordless authentication of users. Federated Client Authentication to use SPIFFE or Kubernetes service account tokens for client authentication. Simplified deployments across multiple availability zones to boost availability. FAPI 2 Final: Keycloak now supports the final specifications of FAPI 2.0 Security Profile and FAPI 2.0 Message Signing. DPoP: The OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) is now fully supported. Improvements include the ability to bind only refresh tokens for public clients, and securing all Keycloak endpoints with DPoP tokens. Read on to learn more about each new feature. If you are upgrading from a previous release, review also the changes listed in the upgrading guide. Security and Standards Passkeys integration (supported) Passkeys are now seamlessly integrated in the Keycloak login forms using both conditional and modal UIs. To activate the integration in the realm, go to Authentication, Policies, Webauthn Passwordless Policy and switch Enable Passkeys to enabled. For more information, see Passkeys. FAPI 2 Final (supported) Keycloak has support for the latest versions of FAPI 2 specifications. Specifications FAPI 2.0 Security Profile and FAPI 2.0 Message Signing are already promoted to Final and Keycloak supports them. Keycloak client policies support the final versions and corresponding client profiles for FAPI 2 are passing the FAPI conformance test suite. Apart from some very minor polishing of existing policies, Keycloak has new client profiles (fapi-2-dpop-security-profile and fapi-2-dpop-message-signing) for the clients that use DPoP and are intended to be FAPI 2 compliant. Thank you to Takashi Norimatsu for contributing this. For more details, see the

## Passkeys support in upcoming Keycloak release (26.4)

DevFeed: [Passkeys support in upcoming Keycloak release (26.4)](<https://devfeed.tech/articles/passkeys-support-in-upcoming-keycloak-release-26-4-31724.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/09/passkeys-support-26-4>)

Author: Peter Skopek

Published: 2025-09-16T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [password](<https://devfeed.tech/tags/password.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.4.0 is announced as adding official passkey support. The feature uses conditional and modal UI, is disabled by default, and can be enabled through the WebAuthn Passwordless Policy. A new conditional credential authenticator can skip 2FA when a passkey was used as the primary credential.

### Source excerpt

Passkeys have been available in Keycloak since version 23.0.0 as a preview feature. We are happy to announce official support for passkeys in upcoming Keycloak 26.4.0. What is passkey? Definition from FIDO Alliance A passkey is a FIDO authentication credential based on FIDO standards, that allows a user to sign in to apps and websites with the same process that they use to unlock their device (biometrics, PIN, or pattern). Passkeys are FIDO cryptographic credentials that are tied to a user's account on a website or application. More info What's new? Passkeys are now seamlessly integrated to Keycloak using both conditional and modal UI. There is no need to modify default browser flow to use passkeys. Passkeys support is not enabled by default. It needs to be enabled in the WebAuthn Passwordless Policy (Authentication -> Policies -> Webauthn Passwordless Policy). There is new Conditional - credential authenticator that checks if a specific credential type (passkey) has been used during the authentication process. It is added to the default browser flow to skip 2FA in case a passkey was used to log in as the primary credential. Further quite hidden passkey support is also in the re-authentication form, where users can choose passkey as well as password. For more information check Keycloak Server Administration Guide. A few examples Let's start form the fresh Keycloak database. The first steps are obvious ones. create admin user create one test user enable passkey support in (Authentication -> Policies -> Webauthn Passwordless Policy) set default required action in (Authentication -> Required actions -> Webauthn Register Passwordless) (This step is not necessary, one can use Account Console to register a passkey.) No need for any other changes. Conditional UI Conditional UI is displayed when other components of the platform supports this UI style and username input field is present. It can be achieved for example on Linux using Google Chrome browser and 1password password man

## Keycloak 26.3.0 released

DevFeed: [Keycloak 26.3.0 released](<https://devfeed.tech/articles/keycloak-26-3-0-released-31714.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/07/keycloak-2630-released>)

Author: Keycloak Team

Published: 2025-07-03T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [migration](<https://devfeed.tech/topics/migration.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [openid](<https://devfeed.tech/topics/openid.md>), [Latency](<https://devfeed.tech/topics/latency.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [latency](<https://devfeed.tech/tags/latency.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [logging](<https://devfeed.tech/tags/logging.md>), [migration](<https://devfeed.tech/tags/migration.md>), [new-feature](<https://devfeed.tech/tags/new-feature.md>), [oauth-2-0](<https://devfeed.tech/tags/oauth-2-0.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [otp](<https://devfeed.tech/tags/otp.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.3.0 is a software release that adds supported 2FA recovery codes, simplifies WebAuthn and Passkeys registration and account linking, expands OAuth 2.0 and OpenID Connect connectivity, improves logging throughput and latency, and introduces experimental rolling updates for patch releases.

### Source excerpt

To download the release go to Keycloak downloads. Highlights This release delivers advancements to optimize your system and improve the experience of users, developers and administrators: Account recovery with 2FA recovery codes, protecting users from lockout. Simplified experiences for application developers with streamlined WebAuthn/Passkey registration and simplified account linking to identity providers via application initiated actions. Broader connectivity with the ability to broker with any OAuth 2.0 compliant authorization server, and enhanced trusted email verification for OpenID Connect providers. Asynchronous logging for higher throughput and lower latency, ensuring more efficient deployments. For administrators, experimental rolling updates for patch releases mean minimized downtime and smoother upgrades. Read on to learn more about each new feature, and find additional details in the upgrading guide if you are upgrading from a previous release of Keycloak. Recovering your account if you lose your 2FA credentials When using for example a one-time-password (OTP) generators as a second factor for authenticating users (2FA), a user can get locked out of their account when they, for example, lose their phone that contains the OTP generator. To prepare for such a case, the recovery codes feature allows users to print a set of recovery codes as an additional second factor. If the recovery codes are then allowed as an alternative 2FA in the login flow, they can be used instead of the OTP generated passwords. With this release, the recovery codes feature is promoted from preview to a supported feature. For newly created realms, the browser flow now includes the Recovery Authentication Code Form as Disabled, and it can be switched to Alternative by admins if they want to use this feature. For more information about this 2FA method, see the Recovery Codes chapter in the Server Administration Guide. Performance improvements to import, export and migration The time

## Pectra Mainnet Announcement

DevFeed: [Pectra Mainnet Announcement](<https://devfeed.tech/articles/pectra-mainnet-announcement-17150.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2025/04/23/pectra-mainnet>)

Author: EF Protocol Support

Published: 2025-04-23T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Transactions](<https://devfeed.tech/topics/transactions.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [abstraction](<https://devfeed.tech/tags/abstraction.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [batching](<https://devfeed.tech/tags/batching.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [protocol-announcements](<https://devfeed.tech/tags/protocol-announcements.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

The Pectra network upgrade is scheduled to activate on Ethereum mainnet on May 7, 2025. The article explains how EIP-7702 adds smart contract capabilities to externally owned accounts and outlines related safety mechanisms.

### Source excerpt

The Pectra network upgrade is scheduled to activate on the Ethereum mainnet on May 07, 2025 at epoch 364032 (10:05:11 UTC)! Mainnet client releases are listed below....

## A Tour of WebAuthn

DevFeed: [A Tour of WebAuthn](<https://devfeed.tech/articles/a-tour-of-webauthn-36613.md>)

Original publisher: [Read original article](<http://www.imperialviolet.org/2024/12/23/tourofwebauthn.html>)

Author: Adam Langley

Published: 2024-12-23T00:00:00Z

Content type: article

Language: en

Sources: [ImperialViolet](<https://devfeed.tech/sources/imperialviolet.md>)

Topics: [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>)

Tags: [conference](<https://devfeed.tech/tags/conference.md>), [html](<https://devfeed.tech/tags/html.md>)

### AI overview

The author announces that a longer work about understanding and using WebAuthn is now available online in HTML. The work expands on earlier posts about WebAuthn and passkeys and was previously distributed as a printed booklet at a FIDO conference.

### Source excerpt

I've done a bunch of posts about WebAuthn/passkeys over time. This year I decided to flesh them out a bit into a longer work on understanding and using WebAuthn. If you were at the FIDO conference in Carlsbad this year, you may have received a physical, printed booklet of the result. It took a while to get around to converting to HTML, but the text is now available online.

## Keycloak 26.0.2 released

DevFeed: [Keycloak 26.0.2 released](<https://devfeed.tech/articles/keycloak-26-0-2-released-31661.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/10/keycloak-2602-released>)

Author: Keycloak Team

Published: 2024-10-24T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [OpenAPI Specification](<https://devfeed.tech/topics/openapi.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [idm](<https://devfeed.tech/tags/idm.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openapi](<https://devfeed.tech/tags/openapi.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.0.2 is a maintenance release published on October 24, 2024. It includes an enhancement for trusted certificate configuration and resolves bugs affecting JavaScript adapters, GUI validation, the Organization API documentation, passkeys, OpenTelemetry initialization, organization features, imports, password validation, CLI handling, and other areas.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #32110 [Documentation] - Configuring trusted certificates - Fully specify truststore path dist/quarkus Bugs #15635 oidc - JavaScript-Adapter LocalStorage#clearExpired does not clear all possible items adapter/javascript #19101 Uncaught (in promise): QuotaExceededError adapter/javascript #20287 When using `oidcProvider` config url (.well-known) it's not possible to use `silentCheckSsoRedirectUri` adapter/javascript #28978 some GUI validation check missing admin/ui #30832 Organization API not available from OpenAPI documentation admin/api #31724 Logout not working after removing Identity Provider of user identity-brokering #33072 Passkeys: Infinite (re-)loading loop on browsers with WebAuthn Conditional UI disabled authentication/webauthn #33844 Wrong documentation link in keycloak-js readme docs #33902 Not persisted config settings prevent server start dist/quarkus #33948 [PERF] OpenTelemetry is initialized even when disabled #33968 Not possible to close dialog boxes when clicking buttons or the close icon admin/ui #33991 Doc CI - broken links error docs #34009 grammatical error in "Managing Organizations" documentation docs #34015 Home URL for security-admin-console is broken admin/ui #34028 Custom keycloak login theme styles.css return error 404 login/ui #34049 Org Invite: `linkExpiration` template variable represents 54 years in minutes organizations #34063 Respect the locale set to a user when redering verify email pages user-profile #34069 Do not show domain match message in the identity-first login when no login hint is provided organizations #34075 Flaky test: org.keycloak.testsuite.broker.KcOidcBrokerTest#testPostBrokerLoginFlowWithOTP_bruteForceEnabled ci #34095 Keycloak 26.0.0/26.0.1 Import Issue: Multiple Realms Not Imported, Duplicated Realm Imported Instead import-export #34151 JS passw

## Why We Transitioned to Clerk for Authentication

DevFeed: [Why We Transitioned to Clerk for Authentication](<https://devfeed.tech/articles/why-we-transitioned-to-clerk-for-authentication-6120.md>)

Original publisher: [Read original article](<https://turso.tech/blog/why-we-transitioned-to-clerk-for-authentication>)

Author: João Gris

Published: 2024-08-15T00:00:00Z

Content type: article

Language: en

Sources: [Turso Blog](<https://devfeed.tech/sources/turso-blog.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Turso](<https://devfeed.tech/topics/turso.md>), [Auth0](<https://devfeed.tech/topics/auth0.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [development](<https://devfeed.tech/tags/development.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [security](<https://devfeed.tech/tags/security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [sso](<https://devfeed.tech/tags/sso.md>), [turso](<https://devfeed.tech/tags/turso.md>)

### AI overview

Turso explains why it moved from a self-built GitHub authentication system to Clerk. The transition addressed growing needs such as MFA, SSO, additional authentication methods, account management, and support for CLI tokens.

### Source excerpt

Learn about how and why we transitioned to Clerk from our own auth system for Turso.

## Recap from KubeCon + CloudNativeCon Europe 2024

DevFeed: [Recap from KubeCon + CloudNativeCon Europe 2024](<https://devfeed.tech/articles/recap-from-kubecon-cloudnativecon-europe-2024-31639.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/04/keycloak-at-kubecon-eu-2024-recap>)

Author: Thomas Darimont

Published: 2024-04-15T00:00:00Z

Content type: article

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>)

Tags: [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [openid](<https://devfeed.tech/tags/openid.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [recap](<https://devfeed.tech/tags/recap.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

A recap of Keycloak's presence at KubeCon + CloudNativeCon Europe 2024, covering talks on OAuth2 Token Exchange for microservice API security, Keycloak's use in CERN's IAM infrastructure, federated IAM for Kubernetes with OpenFGA, and recent support for Passkeys, OAuth 2.1, and OpenID for Verifiable Credentials.

### Source excerpt

After a packed week of fantastic talks at KubeCon + CloudNativeCon Europe 2024 in Paris, we're delighted to share our impressions with the rest of the Keycloak community. Keycloak and OAuth2 Token Exchange for Microservice API Security The presence of Keycloak in many presentations highlighted its importance in the cloud-native ecosystem. Notably, the talk "OAuth2 Token Exchange for Microservice API Security" by Ahmet Soormally & Letz Yaara on OAuth2 Token Exchange (RFC 8693) underscored its application in microservice security and pinpointed areas for Keycloak's enhancement. Efforts to advance the support for Token Exchange are underway, and community feedback is invaluable. Please join the discussion on the current usage of Token Exchange to help us out. Keycloak and the Secrets of the Universe at CERN A standout moment was learning about Keycloak's role at CERN in the talk "The Hard Life of Securing a Particle Accelerator", as shared by Antonio Nappi and Sebastian Lopienski, emphasizing its contribution to securing the particle accelerator's IAM infrastructure. Keycloak supports research on the nature of the universe. How cool is that :) Keycloak, OpenFGA, and Kubernetes Authorizer Jonathan Whitaker's talk "Federated IAM for Kubernetes with OpenFGA" on federated IAM with OpenFGA showcased innovative approaches for managing access to Kubernetes resources through the combination of Keycloak, OpenFGA and a custom Kubernetes Authorizer Web Hook. In particular, the demonstration of temporarily elevated access to Kubernetes resources was very well received. Keycloak: The Leading Edge of AuthN and AuthZ Last but not least, our session, "The Leading Edge of AuthN and AuthZ by Keycloak", presented by Takashi Norimatsu and Thomas Darimont, introduced the latest Keycloak advancements, including support for Passkeys, OAuth 2.1, and OpenID for Verifiable Credentials (OpenID4VC). As part of our talk, we showed the current support for Passkeys and some integration options with

## Keycloak 23.0.0 released

DevFeed: [Keycloak 23.0.0 released](<https://devfeed.tech/articles/keycloak-23-0-0-released-31625.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2023/11/keycloak-2300-released>)

Author: Keycloak Team

Published: 2023-11-23T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [openid](<https://devfeed.tech/topics/openid.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [idm](<https://devfeed.tech/tags/idm.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [oauth-2-0](<https://devfeed.tech/tags/oauth-2-0.md>), [openid](<https://devfeed.tech/tags/openid.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 23.0.0 adds support for FAPI 2 draft client profiles, previews DPoP and Passkeys, expands introspection endpoint flexibility, adds a feature flag for the OAuth 2.0 device authorization grant, and improves WebAuthn interoperability.

### Source excerpt

To download the release go to Keycloak downloads. Highlights OpenID Connect / OAuth 2.0 FAPI 2 drafts support Keycloak has new client profiles fapi-2-security-profile and fapi-2-message-signing, which ensure Keycloak enforces compliance with the latest FAPI 2 draft specifications when communicating with your clients. Thanks to Takashi Norimatsu for the contribution. DPoP preview support Keycloak has preview for support for OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP). Thanks to Takashi Norimatsu and Dmitry Telegin for their contributions. More flexibility for introspection endpoint In previous versions, introspection endpoint automatically returned most claims, which were available in the access token. Now there is new switch Add to token introspection on most of protocol mappers. This addition allows more flexibility as introspection endpoint can return different claims than access token. This is first step towards "Lightweight access tokens" support as access tokens can omit lots of the claims, which would be still returned by the introspection endpoint. When migrating from previous versions, the introspection endpoint should return same claims, which are returned from access token, so the behavior should be effectively the same by default after the migration. Thanks to Shigeyuki Kabano for the contribution. Feature flag for OAuth 2.0 device authorization grant flow The OAuth 2.0 device authorization grant flow now includes a feature flag, so you can easily disable this feature. This feature is still enabled by default. Thanks to Thomas Darimont for the contribution. Authentication Passkeys support Keycloak has preview support for Passkeys. Passkey registration and authentication are realized by the features of WebAuthn. Therefore, users of Keycloak can do passkey registration and authentication by existing WebAuthn registration and authentication. Both synced passkeys and device-bound passkeys can be used for both Same-Device and Cr

## Chrome support for passkeys in iCloud Keychain

DevFeed: [Chrome support for passkeys in iCloud Keychain](<https://devfeed.tech/articles/chrome-support-for-passkeys-in-icloud-keychain-36611.md>)

Original publisher: [Read original article](<http://www.imperialviolet.org/2023/10/18/icloudkeychain.html>)

Author: Adam Langley

Published: 2023-10-18T00:00:00Z

Content type: release

Language: en

Sources: [ImperialViolet](<https://devfeed.tech/sources/imperialviolet.md>)

Topics: [Chrome](<https://devfeed.tech/topics/chrome.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [ios](<https://devfeed.tech/tags/ios.md>), [macos](<https://devfeed.tech/tags/macos.md>), [settings](<https://devfeed.tech/tags/settings.md>), [stable-channel](<https://devfeed.tech/tags/stable-channel.md>), [sync](<https://devfeed.tech/tags/sync.md>), [terminal](<https://devfeed.tech/tags/terminal.md>)

### AI overview

Chrome 118 adds support for creating and accessing passkeys in iCloud Keychain on macOS 13.5 or later. The article explains the required permission for autofill and account-picker access, as well as iCloud account and sync requirements.

### Source excerpt

Chrome 118 (which is rolling out to the Stable channel now) contains support for creating and accessing passkeys in iCloud Keychain. Firstly, I'd like to thank Apple for creating an API for this that browsers can use: it's a bunch of work, and they didn't have to. Chrome has long had support for creating WebAuthn credentials on macOS that were protected by the macOS Keychain and stored in the local Chrome profile. If you've used WebAuthn in Chrome and it asked you for Touch ID (or your unlock password) then it was this. It has worked great for a long time. But passkeys are supposed to be durable, and something that's forever trapped in a local profile on disk is not durable. Also, if you're a macOS + iOS user then it's very convenient to have passkeys sync between your different devices, but Google Password Manager doesn't cover passkeys on those platforms yet. (We're working on it.) So having iCloud Keychain support is hopefully useful for a number of people. With Chrome 118 you'll see an "iCloud Keychain" option appear in Chrome's WebAuthn UI if you're running macOS 13.5 or later: You won't, at first, see iCloud Keychain credentials appear in autofill. That's because you need to grant Chrome permission to access the metadata of iCloud Keychain passkeys before it can display them. So the first time you select iCloud Keychain as an option, you'll see this: If you accept, then iCloud Keychain credentials will appear in autofill, and in Chrome's account picker when you click a button to use passkeys. If you decline, then you won't be asked again. You can still use iCloud Keychain, but you'll have to go though some extra clicks every time. You can change your mind in System Settings -> Passkeys Access for Web Browsers, or you can run tccutil reset WebBrowserPublicKeyCredential from a terminal to reset that permission system wide. (Restart Chrome after doing either of those things.) Saving a passkey in iCloud Keychain requires having an iCloud account and having iCloud K

[Next page](<https://devfeed.tech/topics/passkeys.md?cursor=WyIyMDIzLTEwLTE4VDAwOjAwOjAwKzAwOjAwIiwgIjAxYmZmZTI2LTVkM2EtNDEwNS1iZDVlLTU5MTYzOTY1ZGM5YiJd>)