What Are WebAuthn and Passkeys?
WebAuthn is a W3C standard for authenticating with public-key cryptography instead of a shared secret. A passkey is the credential: a private key kept on the user’s device that signs a challenge, so nothing phishable is ever transmitted or stored on a server. For the agent economy it is a model for how authority should work generally — a key that proves who acted, held by the actor, rather than a secret sitting in someone else’s database waiting to leak.
The pattern, beyond login
In WebAuthn the server stores only a public key and sends a challenge; the device signs it with the private key, which never leaves the device. There is no shared secret to phish, to reuse across sites, or to steal from a breached database.
That is the same shape the estate uses for agent authority: standing lives as a key the actor holds at its own domain, and verification is recomputing a signature rather than trusting a central store — portable, not rented.
Related standards
Questions
Is a passkey the same as two-factor authentication?
It can replace both password and second factor at once, since the device plus a biometric or PIN already proves possession and presence.
What does this have to do with agents?
It is the clearest consumer example of authority as a held key rather than a stored secret — the principle agent identity is built on.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.