Discoverable credentials (formerly Resident Credentials) per WebAuthn L3 6.3 + CTAP2.1 are credentials whose private-key + per-credential metadata (rpId + userHandle + signCount) are stored on the authenticator. The user-handle enables AUTHENTICATION WITHOUT USERNAME - the RP can call navigator.credentials.get() without allowCredentials + the authenticator presents matching credentials to the user for selection. PASSKEYS: marketing name for FIDO2 discoverable credentials that ALSO support multi-device sync. Apple iCloud Keychain (2022) + Google Password Manager (2023) + Microsoft Windows Hello + 1Password + Bitwarden + Dashlane support passkey synchronisation across user devices. BACKUP ELIGIBILITY (BE) + BACKUP STATE (BS) FLAGS in authenticatorData: BE indicates the credential CAN be backed up; BS indicates the credential IS currently backed up. RP USE: BE+BS=11 indicates a synced passkey; BE=0 indicates a single-device credential (security key). Account recovery: passkey sync provides recovery via account sync; single-device credentials require enrolment of multiple authenticators OR recovery code OR identity-verification reset. EXPORT/IMPORT: in 2024-2025 FIDO Alliance is developing credential-exchange-protocol (CXP) for cross-platform passkey portability; until CXP is broadly available, passkeys are typically locked to a single platform's sync ecosystem (Apple to Apple + Google to Google).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.