{"id":2882,"date":"2026-08-26T06:01:35","date_gmt":"2026-08-26T13:01:35","guid":{"rendered":"https:\/\/self-issued.info\/?p=2882"},"modified":"2026-08-26T06:24:45","modified_gmt":"2026-08-26T13:24:45","slug":"third-version-of-w3c-web-authentication-webauthn-is-now-a-standard","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2882","title":{"rendered":"Third Version of W3C Web Authentication (WebAuthn) is Now a Standard"},"content":{"rendered":"<p><span class=\"plain\"><a href=\"https:\/\/www.w3.org\/\"><img decoding=\"async\" align=\"right\" src=\"https:\/\/self-issued.info\/images\/w3c_home.png\" alt=\"W3C logo\"><\/a><\/span>The World Wide Web Consortium (W3C) has published the <a href=\"https:\/\/www.w3.org\/TR\/2026\/REC-webauthn-3-20260825\/\">Web Authentication (WebAuthn) Level 3<\/a> specification as a <a href=\"https:\/\/www.w3.org\/2021\/Process-20211102\/#RecsW3C\">W3C Recommendation<\/a>, meaning that it now a completed standard.  While remaining compatible with the <a href=\"https:\/\/www.w3.org\/TR\/2019\/REC-webauthn-1-20190304\/\">Level 1<\/a> and <a href=\"https:\/\/www.w3.org\/TR\/2021\/REC-webauthn-2-20210408\/\">Level 2<\/a> standards, this third version adds additional features, in part, to enable improvements to user experiences with passkeys.<\/p>\n<p>Meanwhile, between the publication of <a href=\"https:\/\/self-issued.info\/?p=2160\">Level 2 in 2021<\/a> and Level 3 and 2026, the FIDO Alliance published versions <a href=\"https:\/\/fidoalliance.org\/specs\/fido-v2.2-ps-20250714\/fido-client-to-authenticator-protocol-v2.2-ps-20250714.html\">2.2<\/a> and <a href=\"https:\/\/fidoalliance.org\/specs\/fido-v2.3-ps-20260226\/fido-client-to-authenticator-protocol-v2.3-ps-20260226.html\">2.3<\/a> of the FIDO2 Client to Authenticator Protocol (CTAP) specification, which this specification can be used with.  See <a href=\"https:\/\/self-issued.info\/?p=2829\">my post about CTAP 2.3<\/a>.<\/p>\n<p>I highly recommend Tim Cappalli&#8217;s detailed <a href=\"https:\/\/blog.timcappalli.me\/p\/webauthn-3\/\">summary of the changes in Level 3 of WebAuthn<\/a>.<\/p>\n<p>The one thing I&#8217;d add to Tim&#8217;s description of what&#8217;s next for WebAuthn is:<\/p>\n<ul>\n<li><b>Raw Signing Extension<\/b>: <a href=\"https:\/\/github.com\/w3c\/webauthn\/pull\/2078\">PR #2078<\/a> creates a mechanism for signing arbitrary data using a key associated with but different from a WebAuthn credential key pair.<\/li>\n<\/ul>\n<p>The raw signing extension is used the <a href=\"https:\/\/github.com\/wwWallet\/\">wwWallet<\/a> cloud-based digital identity wallet by the <a href=\"https:\/\/siros.org\/\">SIROS Foundation<\/a>.<\/p>\n<p>Congratulations to all who contributed to reaching this important milestone!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The World Wide Web Consortium (W3C) has published the Web Authentication (WebAuthn) Level 3 specification as a W3C Recommendation, meaning that it now a completed standard. While remaining compatible with the Level 1 and Level 2 standards, this third version adds additional features, in part, to enable improvements to user experiences with passkeys. Meanwhile, between [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28,34,19,21,23,25,33],"tags":[],"class_list":["post-2882","post","type-post","status-publish","format-standard","hentry","category-cryptography","category-fido","category-phishing-resistance","category-privacy","category-security","category-specifications","category-w3c"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2882"}],"version-history":[{"count":5,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2882\/revisions"}],"predecessor-version":[{"id":2887,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2882\/revisions\/2887"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}