PPratix.io
Pratix.io · privacy-first utility

Passkey Readiness Checker — Test WebAuthn Support

Check whether this browser and device support passkeys, WebAuthn, platform authenticators and conditional mediation. No credential is created.

Advertisement

The test reads browser capability APIs only. It never creates, stores or transmits a credential.

Pratix.io · Comprehensive guide

Passkeys replace many password flows with credentials protected by your device. This guide explains exactly what this checker tests, how to test the phone or computer in your hands, what WebAuthn results mean, and why this tool never asks for your account details.

What does this tool test?

This tool tests the device and browser you are using now. Open the page on the phone, tablet or computer you want to evaluate, then press the safe support test button. It checks whether the current page is a secure context, whether the browser exposes the PublicKeyCredential API, whether a platform authenticator is available and whether conditional mediation is supported. It does not test a different phone remotely and it does not inspect your accounts.

What is a passkey?

A passkey is a WebAuthn credential that lets a service authenticate you with a device unlock method such as Face ID, Touch ID, Android biometrics, Windows Hello or a device PIN. The private key remains protected by the credential provider; the website receives a public key and a signed response during login. This design can resist many phishing and password-reuse attacks, but the quality of the overall login experience still depends on the service’s implementation and account-recovery choices.

What does Supported mean?

Supported means that the browser exposed the relevant capability API or reported a positive result. It is a strong indication that the device may participate in passkey flows. It is not a promise that every website will work: the site must use HTTPS, implement WebAuthn correctly, create a challenge, verify the response on its server and handle account registration. Browser settings, enterprise policies and the device’s screen lock can also affect the final experience.

What does Unavailable mean?

Unavailable can mean that the browser lacks the API, the page is not secure, the device has no eligible platform authenticator, a permission check failed or the browser does not expose the optional capability. Try the same page in a current browser over HTTPS, ensure a screen lock or biometric method is configured, and test again. A negative result here does not mean that the account is broken; it only describes this browser and device at this moment.

Why is there no email or password field?

The checker is intentionally account-free. It measures browser and device capability without creating a credential, signing into an account or transmitting personal information. A real passkey registration requires a relying party server to issue a challenge and store the public credential. Asking for an email here would not make the capability test more accurate and would introduce unnecessary personal-data collection.

How to test different devices

To test an iPhone, open the tool in Safari on that iPhone. To test Android, open it in Chrome or another supported browser on the Android phone. To test Windows Hello, open the tool on the Windows computer and confirm that Windows Hello is configured. To test a Mac, use a current browser and the Mac’s Touch ID or device security settings. Always press the button on the device you want to measure.

Privacy and limitations

The checker reads browser capability APIs only. It never creates, stores or transmits a passkey. Results can change after browser updates, device policy changes, screen-lock changes or when the page is served without HTTPS. For production implementation, developers must test registration, authentication, recovery, synchronization and cross-device flows with a real WebAuthn server.

What developers must implement on the server

A browser capability check is only the first step of a real passkey rollout. A relying party must generate a fresh challenge, send it to the browser, verify the returned assertion on the server and bind the credential to the correct account. Registration and authentication need clear origin and relying-party identifiers, user verification policy, replay protection and safe error handling. The server should store the credential ID, public key, counter and relevant user metadata—not the private key.

A production service also needs recovery and account-change flows. Users can lose a device, replace a phone or use a synced passkey on another device. Provide a recovery path that is resistant to social engineering and explain which authenticators are supported. Test registration, login, logout, cross-device QR flows, account deletion and recovery on current browsers. This checker deliberately does not perform those server operations; it tells you whether the current environment exposes the foundations a real implementation would use.

Frequently Asked Questions

Does this test my current device?

Yes. Open the tool on the device and browser you want to check, then press the button. The test describes that current environment.

Does it create a passkey?

No. It performs capability checks only and does not create or save a credential.

Is Supported a guarantee that login will work?

No. The website must implement server-side WebAuthn correctly and the account, browser and device settings must allow the flow.

Why is HTTPS important?

WebAuthn is designed for secure contexts. An ordinary insecure HTTP page may not receive the APIs needed for a production passkey flow.

Can I use the result to test my bank account?

The tool does not access your bank or any account. It only provides a general capability signal for the current browser and device.

Pratix.io · Comprehensive guide

Passkeys replace many password flows with credentials protected by your device. This guide explains exactly what this checker tests, how to test the phone or computer in your hands, what WebAuthn results mean, and why this tool never asks for your account details.

What does this tool test?

This tool tests the device and browser you are using now. Open the page on the phone, tablet or computer you want to evaluate, then press the safe support test button. It checks whether the current page is a secure context, whether the browser exposes the PublicKeyCredential API, whether a platform authenticator is available and whether conditional mediation is supported. It does not test a different phone remotely and it does not inspect your accounts.

What is a passkey?

A passkey is a WebAuthn credential that lets a service authenticate you with a device unlock method such as Face ID, Touch ID, Android biometrics, Windows Hello or a device PIN. The private key remains protected by the credential provider; the website receives a public key and a signed response during login. This design can resist many phishing and password-reuse attacks, but the quality of the overall login experience still depends on the service’s implementation and account-recovery choices.

What does Supported mean?

Supported means that the browser exposed the relevant capability API or reported a positive result. It is a strong indication that the device may participate in passkey flows. It is not a promise that every website will work: the site must use HTTPS, implement WebAuthn correctly, create a challenge, verify the response on its server and handle account registration. Browser settings, enterprise policies and the device’s screen lock can also affect the final experience.

What does Unavailable mean?

Unavailable can mean that the browser lacks the API, the page is not secure, the device has no eligible platform authenticator, a permission check failed or the browser does not expose the optional capability. Try the same page in a current browser over HTTPS, ensure a screen lock or biometric method is configured, and test again. A negative result here does not mean that the account is broken; it only describes this browser and device at this moment.

Why is there no email or password field?

The checker is intentionally account-free. It measures browser and device capability without creating a credential, signing into an account or transmitting personal information. A real passkey registration requires a relying party server to issue a challenge and store the public credential. Asking for an email here would not make the capability test more accurate and would introduce unnecessary personal-data collection.

How to test different devices

To test an iPhone, open the tool in Safari on that iPhone. To test Android, open it in Chrome or another supported browser on the Android phone. To test Windows Hello, open the tool on the Windows computer and confirm that Windows Hello is configured. To test a Mac, use a current browser and the Mac’s Touch ID or device security settings. Always press the button on the device you want to measure.

Privacy and limitations

The checker reads browser capability APIs only. It never creates, stores or transmits a passkey. Results can change after browser updates, device policy changes, screen-lock changes or when the page is served without HTTPS. For production implementation, developers must test registration, authentication, recovery, synchronization and cross-device flows with a real WebAuthn server.

Frequently Asked Questions

Does this test my current device?

Yes. Open the tool on the device and browser you want to check, then press the button. The test describes that current environment.

Does it create a passkey?

No. It performs capability checks only and does not create or save a credential.

Is Supported a guarantee that login will work?

No. The website must implement server-side WebAuthn correctly and the account, browser and device settings must allow the flow.

Why is HTTPS important?

WebAuthn is designed for secure contexts. An ordinary insecure HTTP page may not receive the APIs needed for a production passkey flow.

Can I use the result to test my bank account?

The tool does not access your bank or any account. It only provides a general capability signal for the current browser and device.