Client Override Policy
Overview
Configuration
webauthn:
creation_profiles:
default:
rp:
id: 'example.com'
client_override_policy:
user_verification:
enabled: true
allowed_values: ['required', 'preferred']
authenticator_attachment:
enabled: true
allowed_values: ['platform', 'cross-platform']
resident_key:
enabled: true
allowed_values: ['required', 'preferred', 'discouraged']
attestation_conveyance:
enabled: true
allowed_values: ['none', 'indirect', 'direct', 'enterprise']
extensions:
enabled: true
mediation:
enabled: false # disabled by default; opt-in
allowed_values: ['default', 'conditional']Configurable Fields
Field
Default
Default Allowed Values
Description
Examples
Restrict to Platform Authenticators Only
Lock Down All Options
Allow Only Specific Verification Levels
Opt-in Conditional Create from the Client
How It Works
See Also
Last updated
Was this helpful?