WebAuthn Public Response Inspector

Decode supplied WebAuthn public response fields and supported authenticator or attestation metadata.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Inspect response controls

The clientDataJSON member of the response, base64url encoded. Up to 60,000 characters. It is decoded in your browser and never uploaded.

The authenticatorData member, base64url encoded. Up to 60,000 characters. The first 37 bytes carry the relying-party hash, the flags and the sign counter.

Optional. Only the definite-length CBOR subset used by public attestation objects is read. Indefinite lengths, tags, duplicate keys and trailing bytes are refused.

Off by default. Credential IDs and challenges can identify a person or a session, so they stay out of the table, text and download unless you ask for them.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use WebAuthn Public Response Inspector

  1. Supply the clientdatajson (base64url) and authenticatordata (base64url) using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the webauthn response inspector.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: WebAuthn Public Response Inspector

Decode supplied clientDataJSON/authenticator data and supported attestation metadata. This example uses synthetic public data.

You add
clientDataJSON (base64url): eyJ0eXBlIjoid2ViYXV0aG4uY3JlYXRlIiwiY2hhbGxlbmdlIjoiOWMzYTFmNGI3ZDJlNWE2MDgxYjNjNGQ1ZTZmNzA4MTkiLCJvcmlnaW4iOiJodHRwczovL2FwcC5leGFtcGxlLmNvbSIsImNyb3NzT3JpZ2luIjpmYWxzZX0 authenticatorData (base64url): AwoRGB8mLTQ7QklQV15lbHN6gYiPlp2kq7K5wMfO1dwBAAAADA
You get
webauthn.create response: 1 flag set, no attestation object. clientData type | webauthn.create | The ceremony the browser recorded, such as webauthn.create or webauthn.get. clientData origin | https://app.example.com | Scheme, host and port only; any query in the recorded origin is dropped. Cross origin | false | Whether the browser recorded the ceremony as cross origin.

Options

Response bytes
Use the declared base64url fields and supported attestation form. Truncated or unsupported encodings are refused rather than guessed.
Public metadata
Flags, counters and key metadata can help diagnose a captured response. Credential identifiers and origins can still be sensitive.

Supported inputs and limits

Bounded public-response and supported CBOR/COSE inspection only. No enrollment, device prompts, challenge validation, signature or attestation-provenance verification.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Decoded flags are not an authentication decision

A flag or claimed origin describes the supplied bytes. This inspector does not establish that they came from a trusted authenticator, match an expected challenge or satisfy a relying party’s policy. Attestation metadata is decoded without verifying provenance or its signature.

Questions about WebAuthn Public Response Inspector

Does the result authenticate anyone?

No. It decodes supplied fields without a relying party’s expected challenge or trust checks.

Does a flag prove user verification?

It reports a flag in supplied bytes; authenticity of those bytes is not verified.

Will the browser prompt my authenticator?

No. This inspector does not call registration or authentication APIs.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem