W3C Web Authentication Level 3 Recommendation (W3C TR). The WebAuthn API provides: (a) navigator.credentials.create() for REGISTRATION of a new PublicKeyCredential; (b) navigator.credentials.get() for AUTHENTICATION assertion. The API operates between the relying party + the client (user agent / browser) + the authenticator. Level 3 (Recommendation 2024) extends Level 2 (2021) + Level 1 (2019) with: PRF extension for symmetric secret derivation + HMAC operations; conditional UI improvements; cross-origin authentication via iframes; backup eligibility + backup state flags for passkey synchronisation indication; large blob extension for binding additional data; hints for authenticator-selection UX. Extensions: appid + appid-exclude for FIDO U2F migration; hmac-secret; credProtect; credBlob; minPinLength; largeBlobKey; payment for Secure Payment Confirmation; prf for derived keys. RP must use the API with proper user activation + secure context (HTTPS or localhost). Coordinated specs: Credential Management Level 1 (browser credential UI) + Storage Access API + Permissions Policy.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.