Skip to content

Converged Use Cases for the Credential Management API #3

@timcappalli

Description

@timcappalli

Session description

The Credential Management API has rapidly evolved into a critical component of identity on the web. From enabling seamless passkey experiences via WebAuthn to integrating federated identity flows through FedCM, facilitating SMS OTPs with WebOTP, and now facilitating the exchange of verifiable digital credentials via the Digital Credentials API, its scope continues to expand. This proliferation of capabilities sparks a critical discussion: how can these individual strengths be synergized for richer, more secure, and user-friendly identity experiences?

This session aims to explore three key scenarios: first, the concept of multi-type credential for sign-in requests, for example allowing a single API call to solicit a passkey, a password or a federated identity, second, a multi-type credential for identity attributes, for example allowing a single API call to solicit either a federated assertion or a digital credential based on the application's needs; and third, the potential for a method that combines identity claim acquisition (e.g., name and verified email via federation) with simultaneous passkey creation, streamlining initial sign-up and subsequent passwordless authentication.

Session goal

Ideation and requirements gathering

Additional session chairs (Optional)

@samuelgoto

Who can attend

Anyone may attend (Default)

Instructions for meeting planners (Optional)

No response

IRC channel (Optional)

#credman-convergence

Agenda for the meeting.

No response

Scheduling conflicts to avoid (For meeting planners only)

No response

Links to calendar

Meeting materials

Metadata

Metadata

Assignees

No one assigned

    Labels

    sessionBreakout session proposal

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions