How to use WebAuthn Public Response Inspector
- Supply the clientdatajson (base64url) and authenticatordata (base64url) using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the webauthn response inspector.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: WebAuthn Public Response Inspector
Decode supplied clientDataJSON/authenticator data and supported attestation metadata. This example uses synthetic public data.
Options
- Response bytes
- Use the declared base64url fields and supported attestation form. Truncated or unsupported encodings are refused rather than guessed.
- Public metadata
- Flags, counters and key metadata can help diagnose a captured response. Credential identifiers and origins can still be sensitive.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Decoded flags are not an authentication decision
A flag or claimed origin describes the supplied bytes. This inspector does not establish that they came from a trusted authenticator, match an expected challenge or satisfy a relying party’s policy. Attestation metadata is decoded without verifying provenance or its signature.
Questions about WebAuthn Public Response Inspector
Does the result authenticate anyone?
No. It decodes supplied fields without a relying party’s expected challenge or trust checks.
Does a flag prove user verification?
It reports a flag in supplied bytes; authenticity of those bytes is not verified.
Will the browser prompt my authenticator?
No. This inspector does not call registration or authentication APIs.