Delphi WebAuthn Server
Add passkey-based passwordless authentication to your Delphi server. WebAuthn Level 2 / FIDO2 registration and authentication ceremonies, attestation verification, credential storage hooks.
Add passkey-based passwordless authentication to your Delphi server. WebAuthn Level 2 / FIDO2 registration and authentication ceremonies, attestation verification, credential storage hooks.
Implements the WebAuthn relying-party server side — create credential challenges, verify navigator.credentials responses, parse attestation statements and validate assertion signatures.
TsgcWSAPIServer_WebAuthn
Windows, macOS, Linux, iOS, Android
Enterprise
Drop a TsgcWSAPIServer_WebAuthn on a TsgcWebSocketHTTPServer, set WebAuthnOptions.RelyingParty, then handle OnWebAuthnRegistrationSuccessful to store each new passkey and OnWebAuthnAuthenticationGetCredential to load it back at sign in.
uses
sgcWebSocket, sgcWebSocket_Server_APIs, sgcWebAuthn_Classes;
// Server: TsgcWebSocketHTTPServer and WebAuthn: TsgcWSAPIServer_WebAuthn are form fields
procedure TForm1.StartServer;
begin
Server := TsgcWebSocketHTTPServer.Create(nil);
Server.Port := 8443;
Server.SSL := True;
Server.SSLOptions.CertFile := 'server.pem';
Server.SSLOptions.KeyFile := 'server.pem';
Server.SSLOptions.Port := 8443;
WebAuthn := TsgcWSAPIServer_WebAuthn.Create(nil);
WebAuthn.Server := Server;
WebAuthn.WebAuthnOptions.RelyingParty := 'example.com';
WebAuthn.OnWebAuthnRegistrationSuccessful := OnRegistrationSuccessful;
WebAuthn.OnWebAuthnAuthenticationGetCredential := OnGetCredential;
Server.Active := True;
end;
procedure TForm1.OnRegistrationSuccessful(Sender: TObject;
const aRegistration: TsgcWebAuthn_Registration;
const aCredentialRecord: TsgcWebAuthn_CredentialRecord; var Accept: Boolean);
begin
// store the new passkey in your own database
SaveCredential(aCredentialRecord.CredentialId, aCredentialRecord.AsJSON);
end;
procedure TForm1.OnGetCredential(Sender: TObject; const aCredentialId: string;
const aCredentialRecord: TsgcWebAuthn_CredentialRecord; var Found: Boolean);
var
vJSON: string;
begin
// sign in: load the stored passkey back
vJSON := LoadCredential(aCredentialId);
Found := vJSON <> '';
if Found then
aCredentialRecord.ReadJSON(vJSON);
end;
// uses: sgcWebSocket, sgcWebSocket_Server_APIs
TsgcWebSocketHTTPServer *Server = new TsgcWebSocketHTTPServer(this);
TsgcWSAPIServer_WebAuthn *WebAuthn = new TsgcWSAPIServer_WebAuthn(this);
WebAuthn->Server = Server;
WebAuthn->WebAuthnOptions->RelyingParty = "example.com";
Server->Active = true;
A relying-party server that turns a Delphi process into a passkey-aware authentication endpoint.
OnWebAuthnRegistrationOptionsRequest accepts the request for PublicKeyCredentialCreationOptions; the browser invokes navigator.credentials.create(); the server validates the attestation and OnWebAuthnRegistrationSuccessful returns the new credential record.
OnWebAuthnAuthenticationOptionsRequest fills PublicKeyCredentialRequestOptions with the previously stored credential records; the server validates the assertion signature using the stored public key and fires OnWebAuthnAuthenticationSuccessful.
Supports none, packed, fido-u2f, tpm, android-key, android-safetynet and apple attestation statement formats.
Tracks the per-credential signCount to detect cloned authenticators. If the counter regresses, OnWebAuthnAuthenticationError reports an error you can act on.
UserVerification can be set to required, preferred or discouraged per ceremony — the validation step enforces the choice.
OnWebAuthnAuthenticationOptionsRequest hands you the request so you return the right CredentialRecords for the allowCredentials list of the in-progress login. Storage is yours to design.
Authoritative sources for the standards this component implements.
A passkey is a discoverable WebAuthn credential kept by Windows Hello, iCloud Keychain, Google Password Manager or a security key. The server supports the full passkey experience while the credentials stay in your own database.
Request the authentication options without a user name. The browser lists the passkeys it holds for your site, the user picks one, and the server checks the returned userHandle.
With conditional mediation the passkeys appear in the autofill list of the user name field. Add autocomplete="username webauthn" and call startAuthentication(options, true) from /sgcWebAuthn.js.
Register one passkey on the laptop and another on the phone. All the passkeys of an account share one user handle and the authentication options list every one of them.
BackupEligible and BackupState in the credential record tell a synced passkey from a device-bound security key, so you can suggest a second passkey to users with only one device.
Save the record in OnWebAuthnRegistrationSuccessful, look up the credential of a usernameless or autofill sign-in in OnWebAuthnAuthenticationGetCredential, and store the new counter in OnWebAuthnAuthenticationSuccessful.
A signature counter that does not move forward is rejected as a possible clone, and so is a backup eligibility flag that changes between sign-ins. Synced passkeys that always report 0 keep working.
Read Passkeys in Delphi: Passwordless Login With WebAuthn and the Passkeys help topic.
Deep-link to the component reference, grab the ready-to-run demo project, and download the trial.
| Online Help — TsgcWSAPIServer_WebAuthn Full property, method and event reference for this component. | Open | |
| Demo Project — Demos\20.HTTP_Protocol\12.WebAuthn Ready-to-run example project. Ships inside the sgcWebSockets package — download the trial below. | Open | |
| Technical Document (PDF) Features, quick start, code samples for Delphi & C++ Builder and primary-source references — this component only. | Open | |
| User Manual (PDF) Comprehensive manual covering every component in the library. | Open |