loading experience

ASP.NET Core

Passkeys in ASP.NET Core Identity: signing in without passwords

Passkeys resist phishing and are more convenient than passwords: how they arrive in ASP.NET Core 10.

Passkeys in ASP.NET Core Identity: signing in without passwords

Passwords get reused, stolen and guessed. Passkeys, based on the WebAuthn and FIDO2 standards, replace the password with a pair of cryptographic keys: the private key stays on the user's device, protected by fingerprint, face or PIN.

The private key never leaves the user's device.
The private key never leaves the user's device.

Why they are more secure

  • Phishing resistant: a passkey only works on the site it was created for; a fake site cannot use it.
  • No secrets on the server: the server stores only the public key; a database breach reveals no usable credentials.
  • More convenient: nothing to remember, sign in with a gesture.

What changes in ASP.NET Core 10

ASP.NET Core Identity integrates passkey support: registering a passkey for the user, signing in with a passkey and managing the passkeys linked to the account. The Blazor Web App template with individual accounts already includes the necessary pages, a good starting point for other project types too.

A realistic adoption path

  1. Offer passkeys as an additional option to existing users.
  2. Suggest it at the right moment, for example right after a successful sign-in.
  3. Keep a secure recovery method, because users change phones.
  4. When most users have one, consider making the password optional.

In the meantime

builder.Services.Configure<IdentityOptions>(o =>
{
    o.Lockout.MaxFailedAccessAttempts = 5;
    o.Lockout.DefaultLockoutTimeSpan = TimeSpan.FromMinutes(15);
    o.SignIn.RequireConfirmedEmail = true;
});

As long as passwords exist, lockout after failed attempts, confirmed email and two-factor authentication remain essential.

Comments (0)

No comments yet.

Leave a comment