Skip to content

hmac-secret extraction without stored information #870

Answered by LDVG
Meri3252 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

The RP ID, hmac-secret salt(s), and Credential ID are required to be able to retrieve a consistent secret. You can omit the Credential ID if you use discoverable credentials. The client data (challenge) should not be stored.

Hope this helps,
Ludvig

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@Meri3252
Comment options

@LDVG
Comment options

LDVG Jun 5, 2025
Maintainer

@Meri3252
Comment options

@LDVG
Comment options

LDVG Jun 9, 2025
Maintainer

Answer selected by Meri3252
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants