CanoKey supports the WebAuthn (passkey) authentication protocol through the CTAP specification.
| CTAP Version | Firmware Requirement |
|---|---|
| CTAP 2.0 | All versions |
| CTAP 2.1 | Firmware 2.0.0 and later |
| CTAP 2.3 | Firmware 3.1.1 and later |
Supported features include:
Firmware version 2.0.0 adds:
credProtect, credBlob, and largeBlobKey extensionsFirmware version 3.0.0 adds:
Firmware version 3.1.1 adds:
alwaysUv, minimum PIN length, forced PIN change, and long-press reset settingsminPinLength, thirdPartyPayment, and HMAC-secret during credential creation (hmac-secret-mc) extensionsalg = -49) credentials; the default algorithm ID for SM2 changes from -48 to -54alwaysUv is disabledFirmware version 3.0.0 does not support U2F, WebAuthn over USB on iOS 17.4 and 18, or WebAuthn on macOS, including Safari, Firefox, and applications that rely on Apple’s CTAP stack. Firmware version 3.0.2 and later are not affected by these limitations.
CanoKey can be used for two-factor authentication on many websites.
By default, CanoKey does not set a PIN. Some websites and certain features (such as Discoverable Credentials management) require you to set a PIN. Please set it when prompted.
ecdsa-sk / ed25519-sk) for OpenSSH authentication.