web api instance property
AuthenticatorAttestationResponse: attestationObject property
Secure context
The attestationObject property of the
AuthenticatorAttestationResponse interface returns an
ArrayBuffer containing the new public key, as well as signature over the
entire attestationObject with a private key that is stored in the
authenticator when it is manufactured.
As part of the create() call, an authenticator will
create a new key pair as well as an attestationObject for that key pair. The public key
that corresponds to the private key that has created the attestation signature is well
known; however, there are various well known attestation public key chains for different
ecosystems (for example, Android or TPM attestations).
Value
After decoding the CBOR encoded
ArrayBuffer, the resulting JavaScript object will contain the following
properties:
-
authData-
: The Authenticator data for the operation. Note that in
AuthenticatorAssertionResponse, theauthenticatorDatais exposed as a property in a JavaScript object (seeauthenticatorData) while inAuthenticatorAttestationResponse, theauthenticatorDatais a property in a CBOR map.The same
authenticatorDatafield is used by bothAuthenticatorAttestationResponseand byAuthenticatorAssertionResponse. When used in attestation, it contains an optional field,attestedCredentialData. This field is not included when used in theAuthenticatorAssertionResponse. The attestedCredentialData field contains thecredentialIdandcredentialPublicKey.
-
-
fmt- : A text string that indicates the format of the attStmt. The WebAuthn specification defines a number of formats; however, formats may also be defined
in other specifications and registered in an IANA registry. Formats
defined by WebAuthn are:
"packed""tpm""android-key""android-safetynet""fido-u2f""none"
- : A text string that indicates the format of the attStmt. The WebAuthn specification defines a number of formats; however, formats may also be defined
in other specifications and registered in an IANA registry. Formats
defined by WebAuthn are:
-
attStmt- : An attestation statement that is of the format defined by
"fmt". For now, see the WebAuthn specification for details on each format.
- : An attestation statement that is of the format defined by
Examples
See Creating a public key credential for a detailed example.
Specifications
Browser compatibility
See also
create(): the method used to create a statement with a cryptographicchallengewhich signature by the authenticator is contained inattStmt, with the specifiedattestationtransport option.