Creates a real passkey for this site with your device or password manager, then decodes what came back: the attestation format, every authenticator data flag, the AAGUID, and the COSE public key.
Passkeys created here are throwaway test entries. They stay registered with your password manager or device until you remove them, so you may want to delete the this site entry when you are finished. Everything on this page happens between your browser and your authenticator: your files and inputs never leave your device.
Related tools
- JWT GeneratorBuild, sign, and verify JSON Web Tokens with HS256, RS256, or ES256 locally.
- SSH Key GeneratorGenerate an Ed25519 or ECDSA SSH key pair in your browser, with fingerprint and PEM export.
- Self-Signed Certificate GeneratorGenerate a self-signed X.509 certificate and private key for local development, in your browser.
- Certificate DecoderDecode PEM or DER X.509 certificates to read expiry, SANs, issuer, fingerprints, and chain order.
- Hash & ChecksumHash text or files with MD5, SHA-1, SHA-256, SHA-384, and SHA-512 at once, and verify the result against a known hash.
- OAuth Scope DecoderTurn an OAuth scope list into plain English access and an honest risk read.
What it does
Decodes the pieces a passkey ceremony hands back. Paste a base64url attestationObject, raw authenticatorData, or the whole credential JSON from navigator.credentials, and it reports the relying party ID hash, every authenticator data flag (UP, UV, BE, BS, AT, ED), the signature counter, the AAGUID with the provider it belongs to, the credential ID, and the COSE public key with its algorithm and curve. Attestation statements are unpacked too, including the packed format algorithm and whether a certificate chain came with it. When clientDataJSON is present it also shows the ceremony type, challenge, and origin.
How to use it
Paste any of the three shapes into the input and the tool works out which one it got. Registration output starts with the attestation format and statement, authentication output ends with the signature size and user handle. Switch the detail level to full when you need the raw hex for the RP ID hash, credential ID, and authenticator data, plus the complete COSE key as JSON. Every row has its own copy button.
Why this one
Most WebAuthn debuggers are demo pages bolted onto a vendor signup, and they post your credential to their server to parse it. This one decodes in your browser, so your inputs never leave your device, and it names the AAGUID instead of showing you sixteen bytes of hex. There is no account, no request limit, and it keeps working offline.
FAQ
- Does my credential get sent anywhere?
- No. The decoding runs entirely in your browser, your inputs never leave your device, and the page keeps working offline after the first load. Nothing is logged or stored.
- Does it verify the attestation signature?
- No. It decodes and explains the attestation statement, reporting the format, the algorithm, and whether a certificate chain is present, but it never checks the signature or the certificate chain against a root. Real attestation verification belongs on your server against the FIDO Metadata Service, and any tool that claims to do it in a browser tab is not checking anything you should trust.
- Why is my authenticator reporting an all zero AAGUID?
- An AAGUID of sixteen zero bytes means the authenticator did not identify its model. That is normal and expected: platform authenticators return zeros whenever attestation is set to none, which is the default for most passkey registrations, and privacy conscious authenticators use zeros so a credential cannot be traced back to a specific device model. It is not an error and it does not mean the passkey is weaker.
Keyboard shortcuts: press ? anywhere on this page to see them.