Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Dev-to-Dev: Building Hardware-Backed Signatures with Passkeys and CTAP 2.3 Extensions

Solution Category IAM
Type Webinar
Organization Yubico
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Explores extending WebAuthn beyond authentication into cryptographic verification of user intent for high-value actions
  • Covers YubiKey 5.8 capabilities including CTAP 2.3 enhancements and privacy-preserving extensions
  • Relevant for developers building secure approvals, transactions, digital wallets and AI workflows
  • Features live demonstrations and insights from the YubiKey 5.8 Hackathon

Introduction

Yubico is hosting a developer-focused session examining how passkey technology can extend beyond traditional authentication into broader trust verification scenarios. Led by Mario Bodemann, Senior Developer Advocate at Yubico, the session addresses a timely question facing security architects and application developers: now that passkeys have largely addressed the authentication challenge, how can the same cryptographic foundations secure other sensitive operations within modern applications?

Extending WebAuthn Beyond Login

The session centres on capabilities introduced with YubiKey 5.8, which enable developers to apply WebAuthn principles to actions beyond initial user authentication. An emerging WebAuthn signing extension allows applications to cryptographically sign and verify user intent for specific operations, creating hardware-backed proof that a particular user authorised a particular action at a particular time.

This represents a meaningful evolution in how organisations can approach transaction security. Rather than relying solely on session-based trust established at login, applications can require cryptographic confirmation for individual high-value operations. The practical applications span approvals workflows, financial transactions, digital wallet operations and increasingly relevant AI-driven processes where verifiable human authorisation carries significant weight.

Technical Foundations

The technical discussion covers CTAP 2.3 enhancements that underpin these expanded capabilities. CTAP, the Client to Authenticator Protocol, defines how browsers and applications communicate with hardware security keys. Version 2.3 introduces refinements that support more sophisticated signing operations while maintaining the privacy characteristics that have made passkeys attractive for consumer and enterprise deployments alike.

Privacy-preserving extensions feature prominently in the session content. As organisations seek to verify user intent without unnecessarily exposing user identity or behaviour patterns, these extensions provide mechanisms for obtaining cryptographic assurance while limiting data exposure. This balance between security verification and privacy protection reflects broader industry movement toward privacy-by-design principles in authentication systems.

Practical Implementation Insights

The session takes an interactive, developer-to-developer approach with live demonstrations showing how these concepts translate into working implementations. Attendees will see practical strategies for building hardware-backed trust into applications, moving from theoretical understanding to actionable development patterns.

Project highlights from the recent YubiKey 5.8 Hackathon provide additional context, showcasing how developers encountering these technologies for the first time have applied them to real-world scenarios. These examples offer insight into both the possibilities and practical considerations that emerge during implementation.

Who Should Attend

This session is designed for developers and security engineers working on applications where user intent verification matters. Those building financial services platforms, enterprise approval systems, digital identity solutions or AI-integrated workflows will find the content directly applicable. Familiarity with WebAuthn fundamentals and passkey concepts will help attendees extract maximum value from the technical demonstrations.