Start Here

Product Overview

Understand how OmniPasskey fits into a Shibboleth deployment, how users interact with the platform, and which deployment choices are available before you begin installation.

What OmniPasskey does

OmniPasskey adds passkey registration, policy enforcement, and passkey authentication to a Shibboleth environment. It gives users a customer-facing management experience while providing administrators with the controls needed to manage which devices can register and authenticate.

When a user registers a passkey through My Account, it is immediately available for Shibboleth sign-in. Changes to passkeys and policy take effect consistently across the management and sign-in experiences.

One platform, two runtime surfaces.

The management interface handles registration and lifecycle management, while the IdP integration handles sign-in. Passkeys, rules, and settings remain aligned across both experiences.

Core components

Management Interface

Customer-facing passkey management

The management interface gives users a place to register and manage passkeys and gives authorized staff the tools to support users and manage policy.

Shared Database

Authoritative passkey data

The shared database keeps passkeys, policy settings, device rules, and system activity consistent between registration, management, and sign-in.

IdP Plugin

Passkey authentication for Shibboleth

The plugin adds passkey authentication, optional username collection, optional inline registration, MFA integration, and shared browser client-hint support to the Shibboleth IdP.

Shibboleth Integration

Authorization and trust boundaries

Shibboleth SP protects the customer-facing app and can also enforce admin and helpdesk authorization rules. The IdP continues to control the surrounding authentication framework.

User roles

Role Typical use Available capabilities
End user Register and manage personal passkeys Use New Passkey and My Account to register, view, rename, and delete personal passkeys; use My History to review personal activity
Helpdesk Support and investigate user issues Use Manage Credentials, System Logs, and Dashboard to investigate activity and remove passkeys during support
Administrator Set policy and oversee the service Everything helpdesk can do, plus Manage Rules and Manage Settings

Passkey lifecycle

  1. A user opens My Account, selects New Passkey, and follows the instructions on Register Passkey.
  2. OmniPasskey applies the current registration settings and device rules.
  3. The new passkey appears in My Passkeys and becomes available for Shibboleth sign-in.
  4. The user can rename or delete it from My Passkeys, while authorized staff can support the user through Manage Credentials.

WebAuthn Level 3 experience

OmniPasskey uses WebAuthn Level 3 browser features to streamline passkey sign-in, optional enrollment, and credential management while preserving fallbacks for older or unsupported clients.

  • Conditional passkey sign-in: capable browsers can offer discoverable passkeys through their account-selection experience without first requiring a username. The passkey and username-based paths remain available.
  • Conditional passkey creation: operators can opt into automatic inline enrollment after a successful saved-password sign-in. A capable browser and password manager can create the passkey without another OmniPasskey interaction; the normal setup control remains available when automatic creation is unavailable, ineligible, declined, or times out.
  • Guided browser prompts: ordered security-key, client-device, and hybrid hints can steer registration and sign-in toward the most relevant local, external-key, or cross-device experience. These hints do not override device or registration policy.
  • Sync and discoverability details: credential pages distinguish synced credentials, credentials that can be synced, single-device credentials, and credentials whose status was not reported. They also show whether a newly registered credential was reported as discoverable.
  • Saved passkey updates: supported browsers and password managers keep their saved passkey information current after rejected registrations, user deletions, and visits to My Passkeys. Unsupported browsers continue to work without these automatic updates.
Browser and provider support still controls availability.

OmniPasskey checks browser capabilities before starting conditional experiences. Unsupported clients continue to use standard WebAuthn registration and sign-in.

Deployment choices

Container management interface

Use the supplied container build context when you want OmniPasskey packaged as a dedicated SP-facing application image.

Package-based management interface

Use the native package path when you already operate an Apache and Shibboleth SP host and want to install OmniPasskey into that environment.

Database backend choice

OmniPasskey supports PostgreSQL and MySQL/MariaDB as the shared credential and policy store.

Optional capabilities

Usernameless passkeys Conditional mediation Conditional passkey creation Passkey as MFA factor Inline registration after password auth Per-device-type allow and block rules Attestation-based registration policy Browser client-hint controls

Inline registration

If enabled, the IdP can offer passkey registration immediately after a successful password-based login. Standard inline setup is the default and waits for the user to select the setup button. Operators can opt into Conditional Create, which lets a capable browser and default password manager automatically create and save a passkey after a saved-password login without another site interaction or prominent WebAuthn prompt. The provider may show a completion notice, and the fallback remains available whenever automatic creation is ineligible or declined.

Device policy

OmniPasskey can apply rules by authenticator AAGUID. Operators can choose whether specific device types are allowed to register, allowed to authenticate, or restricted to MFA-only usage.

Registration controls

Manage Settings lets operators control Registration Allowed Origins, Backup Eligibility Policy, Inline Registration Experience, Attestation Conveyance Preference, Allow Untrusted Registrations, Require Resident/Discoverable Key, Authenticator Attachment, Registration User Verification, Preferred COSE Algorithms, and the ordered client hints used for registration and sign-in. My Passkeys and Manage Credentials also report whether the browser identified a newly registered passkey as discoverable.

OmniPasskey customer documentation. Copyright .