MojoAuth Blog - Passwordless Authentication & Identity Solutions
Comprehensive guides on modern authentication methods including PassKeys, WebAuthn, FIDO2, OTP, Magic Links, Social Sign-In, Enterprise SSO, and passwordless solutions. Your complete resource for implementing secure, scalable authentication systems.
Featured
WebAuthn Attestation: Why "none" Is the Right Default
What to Store When You Register a Passkey (and the Two Fields Everyone Forgets)
Best Enterprise Identity and Access Management (IAM) Software
Articles
Never Use an Email as Your WebAuthn user.id
The WebAuthn user id must never hold an email address. Here is what the spec forbids, what breaks when you ignore it, and what to store instead.
Server-Side Passkey Registration: What the Spec Doesn't Tell You
WebAuthn server registration, beyond the spec: verify the attestation response, store AAGUID and BE/BS, and ship the parts the codelab skips.
Choosing Your RP ID: The Passkey Decision You Can't Undo
Your WebAuthn RP ID is permanent. Get the scope wrong and you invalidate every passkey you have issued. How to pick apex vs subdomain, safely.
Known Broken Passkey Combinations (and Workarounds)
Passkey not working in a browser? Here are the exact browser, OS, and password manager combinations that break passkeys in 2026, with a workaround for each.
Passkey AAGUIDs: Which Password Manager Is Your User Actually Using?
A passkey AAGUID reference: map the 16-byte authenticator ID to iCloud Keychain, Google Password Manager, 1Password, and more, and use it in support and analytics.
Conditional UI Browser Support: Where Passkey Autofill Actually Works
Conditional UI browser support decoded: which Chrome, Safari, and Firefox versions run passkey autofill, which OS pairings break it, and how to detect it.