fido2_server library
Public API for the FIDO2 server (WebAuthn).
Classes
- AttestationResult
- Verified attestation evidence. A valid signature does not establish trust in the authenticator vendor. Validate trustPath against application trust anchors/metadata before relying on device identity.
- AttestedCredentialData
-
Data parsed from the
attestedCredentialDatablock of anauthenticatorDatabuffer. This contains the credential information. - AuthenticationResult
- Verified state to persist atomically after successful authentication.
- AuthenticatorData
-
A structured representation of the
authenticatorDatabuffer returned by an authenticator. - CoseConfiguration
- CoseKey
- Parsing checks structure. validate checks mathematical validity in Rust.
- EcdhEsHkdf256
- Ed25519
- EdDSA
- ES256
- Fido2Config
- Fido2Server
- WebAuthn server ceremonies. Callers must store challenges server-side, bind them to the user/session, expire them, and atomically consume them once. Registration verifies none/packed attestation and the credential public key. Certificate trust is delegated to Fido2Config.attestationVerifier.
- MLDSA
- MLDSA44
- MLDSA65
- MLDSA87
- RegisteredCredential
- RegistrationRequest
- RegistrationResult
- The result of a successful registration verification.
- RustCrypto
- All cryptographic operations use the shared Rust native/WASM core.
- SM2
- Sm2Configuration
- Explicit EC2 compatibility profile: SM2 has no IANA COSE allocation.
- UnsupportedKey
- VerificationResult
- The result of a successful assertion (verification).
Enums
- AttestationConveyancePreference
- WebAuthn attestation conveyance preference sent to the client.
- AttestationType
- The kind of proof verified during registration, independent of trust.
- SignatureAlgorithm
- SignatureEncoding
Typedefs
- AttestationVerifier = bool Function(AttestationResult attestation)
- Optional synchronous application policy, called after protocol and signature validation for every registration (including none/self). Return false to reject. For basic attestation, the application owns certificate path, validity, revocation and metadata trust checks.