Proposed Advancement of Web Authentication: An API for accessing Public Key Credentials Level 3 to W3C Recommendation | 2026 | News

Today, the W3C Team proposed advancing Web Authentication: An API for accessing Public Key Credentials Level 3 to W3C Recommendation. This specification was published by the Web Authentication Working Group as a Candidate Recommendation Snapshot on 26 May 2026. This specification defines an API enabling the creation and use of strong, attested, scoped, public key-based credentials by web applications, for the purpose of strongly authenticating users. Conceptually, one or more public key credentials, each scoped to a given WebAuthn Relying Party, are created by and bound to authenticators as requested by the web application. The user agent mediates access to authenticators and their public key credentials in order to preserve user privacy. Authenticators are responsible for ensuring that no operation is performed without user consent. Authenticators provide cryptographic proof of their properties to Relying Parties via attestation. This specification also describes the functional model for WebAuthn conformant authenticators, including their signature and attestation functionality.

Source: The World Wide Web Consortium

Leave a Reply

Your email address will not be published. Required fields are marked *