ClientN Shows How to Add Passkey Login Without Collecting User Emails
A developer building ClientN has published an open-source reference integration demonstrating how small websites can implement passkey-based sign-in without storing user email addresses. The system assigns each user a site-specific clientn_id after passkey confirmation, meaning no password or email is ever transmitted to the site's server. The five-step server flow covers session creation, browser binding via HttpOnly cookies, callback signature verification, and single-use session consumption to prevent race conditions. The reference code is available in Node.js and PHP under an MIT licence, with a test suite covering attacks such as cross-site requests, forged callbacks, and expired logins. Sites must register a domain at clientn.com and receive signed callbacks over HTTPS, making localhost testing unsuitable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in