Reshaping user authentication and identity verification

Chrome for DevelopersAbout 5 min readMay 27, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

Credential Manager, passwords, passkeys, Federated Credential Management (FedCM), digital credentials, device-bound session credentials (DBSC), password managers, seamless credential sharing, digital asset links, related origin requests, passkey syncing, password autofill, FIDO Alliance, identity federation, eIDAS 2.0, Wallet API, session hijacking, cookies, cryptographic key pair, TPM.

Credential Manager for the Web

  • Problem: Multiple sign-in options (passwords, 2FA, phone verification, magic links, passkeys, identity federation) create a confusing user experience.
  • Solution: Credential Manager API for the web, mirroring the Android experience.
  • Functionality: Displays available accounts (passkeys, passwords synced by Google Password Manager) when the user clicks "Sign In."
  • Fallback: If no credentials are available, the user is redirected to the normal sign-in experience.
  • Current Status: Developer trial available by enabling the experimental web platform features flag and using the provided code snippet. Supports passwords and passkeys. Working on adding support for identity federation.
  • Future Plans: Origin trial planned for the year to test with real users.

Password Management Improvements

  • Problem: Users often don't follow password security best practices.
  • Solution: Improvements to Google Password Manager.
  • Automated Password Change: Uses AI to automatically replace compromised passwords with new, strong ones. Initial version works with a subset of websites, expanding in the future.
  • HTML Form Optimization:
    • Use autocomplete="current-password" for the current password field.
    • Use autocomplete="new-password" for the new password field.
  • Well-Known URL: Set up a redirect on your website for the path .well-known/change-password to point to your password change form.
  • Seamless Credential Sharing: Establishes an association between domains and apps, allowing password managers to offer saved credentials across properties.
    • Example: eBay improved sign-in success rate by 10% by implementing seamless credential sharing.
    • Implementation: Use digital asset links by adding a JSON file to the server at .well-known/assetlinks.json and submitting metadata to the app's manifest file. Google Play Console can generate the JSON snippet.
  • Related Origin Requests: Adopt related origin requests to ensure passkeys are available across your domains.

Passkeys

  • Definition: A better password offering improved security and usability.
  • Passkey Syncing: Google Password Manager now supports passkey syncing across Android, Windows, macOS, iOS, ChromeOS, and Linux.
  • Preferring On-Device Passkeys: New way to request passkeys that prioritizes those available on the current device by setting mediation to "immediate". If no passkeys are available, the user is authenticated another way. Aiming for origin trial later this year.
  • Automatic Passkey Creation API: Allows requesting the user's password manager to create a passkey automatically after a successful password sign-in. Available in Chrome 136 on desktop and coming soon to Android.
  • Signal API: Lets password managers know when a user deletes a passkey on the site, ensuring only usable passkeys are presented during sign-in. Available in Chrome on desktop with Google Password Manager and coming soon to Android.
  • Password Manager Switching: Easier way to switch between password managers, allowing users to securely import and export their passwords and passkeys based on FIDO Alliance standards.
  • Improved Autofill Experience: Trigger the autofill dropdown by ensuring the form accepts passwords and passkeys and setting autofocus on the input field.
  • Adoption Benefits: Increased sign-in success rates and quicker sign-ins.

Federated Credential Management (FedCM)

  • Definition: A simple way for websites to sign users up without requiring a new username and password, using identity providers.
  • Privacy: More privacy-preserving than traditional methods because it doesn't require third-party cookies.
  • Adoption: Hundreds of thousands of websites are using FedCM.
  • Passive Mode: Showing available accounts when a user visits a web page.
  • Active Mode: Triggered when a user actively indicates they want to sign in (e.g., clicking a "Sign in with..." button). Provides a seamless browser-mediated experience without leaving the website. Pinterest is already using FedCM active mode. Opt-in by setting mode to "active" when invoking the FedCM API.
  • Multiple Identity Providers: Support for multiple identity providers in passive mode, starting from Chrome 136.
  • Verified Email Address: Exploring ways to use identity federation to request a verified email address on sign-up forms via autofill, removing the need for email confirmations.

Digital Credentials

  • Definition: Digital counterparts to identity documents like driving licenses and passports.
  • Regulations: New regulations like eIDAS 2.0 may require verifying user identity or age using digital credentials.
  • Digital Credentials API: Allows requesting digital credentials to verify user identity or age.
  • Example: Verifying if a user is over 21. The site only learns that the user is over 21 and nothing more.
  • Wallet Integration: Users can select a suitable credential from a wallet on their device (e.g., Google Wallet).
  • Current Status: Available in origin trial on Chrome on Android. Some Google account users can present a valid digital credential to verify their date of birth.
  • Cross-Device Usage: Use digital credentials on desktop by scanning a QR code with an Android device that holds the credential.
  • Provisioning: Actively working on extending the Digital Credentials API to allow users to provision credentials into a wallet app.

Device-Bound Session Credentials (DBSC)

  • Problem: Session hijacking via stolen cookies.
  • Solution: DBSC, a new protocol to protect user sessions.
  • Functionality: Sites request the creation of a cryptographic key pair. The site periodically challenges the browser to check if it still possesses the private key.
  • Security: Private keys are stored securely on the device, making exfiltration expensive.
  • Current Status: Started an origin trial in Chrome 135, limited to Windows machines with a TPM. Plans to expand to other platforms and storage mechanisms.

Conclusion

The presentation covers a range of improvements to authentication and identity management in Chrome and Android, focusing on enhanced security, usability, and privacy. Key takeaways include the introduction of Credential Manager for the web, advancements in password management and passkey adoption, the expansion of FedCM with active mode and multiple identity provider support, the exploration of digital credentials, and the development of DBSC to mitigate session hijacking. The speakers encourage developers to adopt these new features and provide feedback.

AI summaries can miss context or contain errors. Check important details against the original video.

MAKE IT YOURS

Read. Remember. Reuse.

Free tools

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.