WebAuthn Registration and Assertion Debugger

WebAuthn Registration and Assertion Debugger

Inspect credential JSON, client data, authenticator flags, counters, attestation, and COSE evidence locally.

WebAuthn decoding is structural. The debugger does not enroll a credential, validate an origin server, or establish authenticator trust.

CBOR parsing is bounded by local byte, depth, and collection limits.
Credential JSONnavigator.credentials JSON shape
advisorywebauthn.signature_unverified · $.response.signature · The structural debugger has not verified the assertion signature or authenticator trust chain.
StatusReviewable
Typewebauthn.get
Originhttps://app.example.test
Flags
Credential reviewRaw credential bytes are summarized
{
  "status": "reviewable",
  "summary": {
    "credentialId": "fict…",
    "type": "webauthn.get",
    "origin": "https://app.example.test",
    "challengePresent": true,
    "clientDataKeys": [
      "challenge",
      "origin",
      "type"
    ],
    "authenticator": {
      "rpIdHash": "0100000000000000000000000000000000000000000000000000000000000000",
      "flags": [],
      "flagByte": 0,
      "signCount": 0,
      "extensionBytes": 0
    },
    "attestationFormat": null,
    "extensionKeys": []
  }
}