passkey-types
Rust type definitions for the webauthn and CTAP specifications
0.5.0
4.7M downloads/mo
#4668 most downloaded on crates.io
1Password/passkey-rs
What this package is like to depend on
Last release 7 months ago
07 Jan 2026
Ships fairly regularly
a new release about every 5 months
Most releases are documented
notes for 6 of 7 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
7 releases · first in 2023
1 release in the last 12 months
see the full history below
Release timeline
7 releases · Feb 2023 to Jan 2026Releases
latest 7-
0.5.007 Jan 2026Release notes
Open source →- Migrate project to Rust 2024 edition
passkey-authenticator v0.5.0
- Ignore the deprecated
rkoption in requests (#67) - ⚠ BREAKING: Add
user_handleas an optional parameter inCredentialStore::find_credentials
to allow filtering onuser_handle. (#67) - Stop returning an error when we find credentials in the
exclude_credentialslist.
This allows for updating/replacing credentials should the user so wish. (#67) - Fix hmac-secret logic around the second salt (#67)
- ⚠ BREAKING: Fix Ctap2Api trait to correctly call the concrete method to prevent recursion (#67)
- ⚠ BREAKING: The
UserValidationMethodtrait has been updated to useUiHint
to give the implementation more information about the request, which can be used
to decide whether additional validations are needed. To reflect this, the
UserValidationMethodtrait now also returns which validations were performed. (#76) - ⚠ BREAKING: Change the
CredentialStoreandUserValidationMethodassociated type constraint
to a newPasskeyAccessortrait instead of theTryInto<Passkey>, making it possible to use a
custom passkey representation type that goes throughout the entire flow without losing any
additional information through a conversion. (#87) - ⚠ BREAKING: The
Ctap2Api::get_infomethod now returns a boxed response due to the size of
the response. (#88)
passkey-client v0.5.0
- ⚠ BREAKING: Add support for RelatedOrigins to the RpIdVerifier through a generic fetcher (#67)
passkey-types v0.5.0
- Make output types Hashable in Swift code gen (#67)
- Support stringified booleans in webauthn requests (#67)
- Be more tolerant to failed deserialization of optional vectors (#67)
- ⚠ BREAKING: Add
usernameanduser_display_nameto thePasskeytype and its mock builder. (#87) - Update CTAP2 types to ignore unknown values during deserialization,
just like their WebAuthn equivalents. (#88) - ⚠ BREAKING: Update
ctap2::get_info::Responseto have all the fields from ctap 2.2 (#88)
Release notes
Open source →- Ignore the deprecated
rkoption in requests (#67) - ⚠ BREAKING: Add
user_handleas an optional parameter inCredentialStore::find_credentialsto allow filtering onuser_handle. (#67) - Stop returning an error when we find credentials in the
exclude_credentialslist. This allows for updating/replacing credentials should the user so wish. (#67) - Fix hmac-secret logic around the second salt (#67)
- ⚠ BREAKING: Fix Ctap2Api trait to correctly call the concrete method to prevent recursion (#67)
- ⚠ BREAKING: The
UserValidationMethodtrait has been updated to useUiHintto give the implementation more information about the request, which can be used to decide whether additional validations are needed. To reflect this, theUserValidationMethodtrait now also returns which validations were performed. (#76) - ⚠ BREAKING: Change the
CredentialStoreandUserValidationMethodassociated type constraint to a newPasskeyAccessortrait instead of theTryInto<Passkey>, making it possible to use a custom passkey representation type that goes throughout the entire flow without losing any additional information through a conversion. (#87) - ⚠ BREAKING: The
Ctap2Api::get_infomethod now returns a boxed response due to the size of the response. (#88)
-
0.4.017 Dec 2024 -
0.3.013 Sep 2024Release notes
Open source →- Added: support for signature counters
- ⚠ BREAKING: Add
update_credentialfunction toCredentialStore(#23). - Add
make_credentials_with_signature_countertoAuthenticator.
- ⚠ BREAKING: Add
- ⚠ BREAKING: Merge functions in
UserValidationMethod(#24)- Removed:
UserValidationMethod::check_user_presence - Removed:
UserValidationMethod::check_user_verification - Added:
UserValidationMethod::check_user. This function now performs both user presence and user verification checks. The function now also returns which validations were performed, even if they were not requested.
- Removed:
- Added: Support for discoverable credentials
- ⚠ BREAKING: Added:
CredentialStore::get_infowhich returnsStoreInfocontainingDiscoverabilitySupport. - ⚠ BREAKING: Changed:
CredentialStore::save_credentialnow also takesOptions. - Changed:
Authenticator::make_credentialsnow returns an error if a discoverable credential was requested but not supported by the store.
- ⚠ BREAKING: Added:
- Added: support for signature counters
-
0.2.014 Dec 2023Release notes
Open source →Most of these changes are adding fields to structs which are breaking changes due to the current lack of builder methods for these types. Due to this, additions of fields to structs or variants to enums won't be marked as breaking in this release's notes. Other types of breaking changes will be explicitly called out.
- ⚠ BREAKING: Update
bitflagsfrom v1 to v2. This meansctap2::Flagsno longer implementPartialOrd,OrdandHashas those traits aren't applicable. - Added a
transportsfield toctap2::get_info::Response - Changes in
webauthn::PublicKeyCredential:- ⚠ BREAKING:
authenticator_attachmentis now optional - ⚠ BREAKING:
client_extension_results's type has been renamed fromAuthenticationExtensionsClientOutputstoAuthenticatorExtensionsClientOutputs
- ⚠ BREAKING:
- Changes for
webauthn::PublicKeyCredentialRequestOptions:timeoutnow supports deserializing from a stringified numberuser_verificationwill now ignore unknown values instead of returning an error on deserialization- Add
hintsfield (#9) - Add
attestationandattestation_formatsfields
- Changes for
webauthn::AuthenticatorAssertionResponse- Add
attestation_objectfield
- Add
- Changes for
webauthn::PublicKeyCredentialCreationOptions:timeoutnow supports deserializing from a stringified number- Add
hintsfield (#9) - Add
attestation_formatsfield
- Fix
webauthn::CollectedClientDataJSON serialization to correctly follow the spec. (#6)- Add
unknown_keysfield - Always serializes
cross_originwith a boolean even if it is set toNone - ⚠ BREAKING: Remove from
#[typeshare]generation as#[serde(flatten)]onunknown_keysis not supported.
- Add
- Add
webauthn::ClientDataType::PaymentGetvariant. - Make all enums with unit variants
Clone,Copy,PartialEqandEq - Add support for the
CredPropsextension withauthenticatorDisplayName
- ⚠ BREAKING: Update
-
0.1.128 Jul 2023 -
0.1.022 Feb 2023Release notes
Open source →A new crate! This crate houses the swappable cryptographic backends for different libraries should you wish/need to use a different set of libraries than the default RustCrypto libraries. As always PRs are accepted to add new backends should you wish to not use plenty of newtypes to get around the orphan rules.
- New
RngBackendtrait which replaces the pre-existingpasskey-types::rand::random_vecfunction. Use this new method aspasskey-crypto::rng::Rng::random_vec.
- New
-
0.0.108 Feb 2023Nothing published for this version