Maktub · issue #120

WebAuthn PRF probe

Checks whether this browser can derive a stable secret from a passkey — the feature Maktub accounts depend on. Run it once per browser, then paste the report into the issue.

Not run yet
Run step 1, then step 2. Takes about thirty seconds.

Which provider are you testing?

The passkey sheet offers several — iCloud Keychain, Chrome profile, your phone, a security key. Each can answer differently on the same browser, so name the one you pick. It goes into the report.

Environment

  1. 01 Create a test passkey

    Asks for PRF at creation. Some browsers hand back the secret here; others only on first use — that difference is what we're measuring.

    Already made one for this provider on an earlier run? Skip straight to step 2 — it finds any passkey you already have here.

  2. 02 Use it twice

    Two sign-ins in a row. The secret must come back identical both times, or a key derived from it would open nothing. If the picker lists several, choose the one named for the provider you just tested — each run is labelled with its provider and the time.

  3. 03 Autofill sign-in — optional

    Tap the field below. If your passkey appears in the dropdown, pick it. This is the one-tap flow we'd like on the real sign-in screen.

Report for issue #120

Run the steps above to generate a report.