Delphi WebAuthn Server

Add passkey-based passwordless authentication to your Delphi server. WebAuthn Level 2 / FIDO2 registration and authentication ceremonies, attestation verification, credential storage hooks.

TsgcWSAPIServer_WebAuthn

Implements the WebAuthn relying-party server side — create credential challenges, verify navigator.credentials responses, parse attestation statements and validate assertion signatures.

Component class

TsgcWSAPIServer_WebAuthn

Platforms

Windows, macOS, Linux, iOS, Android

Edition

Enterprise

Mount the relying party, store credentials

Drop a TsgcWSAPIServer_WebAuthn on a TsgcWebSocketHTTPServer, set WebAuthnOptions.RelyingParty, then handle OnWebAuthnRegistrationSuccessful to store each new passkey and OnWebAuthnAuthenticationGetCredential to load it back at sign in.

uses
  sgcWebSocket, sgcWebSocket_Server_APIs, sgcWebAuthn_Classes;

// Server: TsgcWebSocketHTTPServer and WebAuthn: TsgcWSAPIServer_WebAuthn are form fields
procedure TForm1.StartServer;
begin
  Server := TsgcWebSocketHTTPServer.Create(nil);
  Server.Port := 8443;
  Server.SSL  := True;
  Server.SSLOptions.CertFile := 'server.pem';
  Server.SSLOptions.KeyFile  := 'server.pem';
  Server.SSLOptions.Port     := 8443;

  WebAuthn := TsgcWSAPIServer_WebAuthn.Create(nil);
  WebAuthn.Server := Server;
  WebAuthn.WebAuthnOptions.RelyingParty := 'example.com';
  WebAuthn.OnWebAuthnRegistrationSuccessful := OnRegistrationSuccessful;
  WebAuthn.OnWebAuthnAuthenticationGetCredential := OnGetCredential;

  Server.Active := True;
end;

procedure TForm1.OnRegistrationSuccessful(Sender: TObject;
  const aRegistration: TsgcWebAuthn_Registration;
  const aCredentialRecord: TsgcWebAuthn_CredentialRecord; var Accept: Boolean);
begin
  // store the new passkey in your own database
  SaveCredential(aCredentialRecord.CredentialId, aCredentialRecord.AsJSON);
end;

procedure TForm1.OnGetCredential(Sender: TObject; const aCredentialId: string;
  const aCredentialRecord: TsgcWebAuthn_CredentialRecord; var Found: Boolean);
var
  vJSON: string;
begin
  // sign in: load the stored passkey back
  vJSON := LoadCredential(aCredentialId);
  Found := vJSON <> '';
  if Found then
    aCredentialRecord.ReadJSON(vJSON);
end;
// uses: sgcWebSocket, sgcWebSocket_Server_APIs
TsgcWebSocketHTTPServer *Server = new TsgcWebSocketHTTPServer(this);
TsgcWSAPIServer_WebAuthn *WebAuthn = new TsgcWSAPIServer_WebAuthn(this);
WebAuthn->Server = Server;
WebAuthn->WebAuthnOptions->RelyingParty = "example.com";
Server->Active = true;

What's inside

A relying-party server that turns a Delphi process into a passkey-aware authentication endpoint.

Registration ceremony

OnWebAuthnRegistrationOptionsRequest accepts the request for PublicKeyCredentialCreationOptions; the browser invokes navigator.credentials.create(); the server validates the attestation and OnWebAuthnRegistrationSuccessful returns the new credential record.

Authentication ceremony

OnWebAuthnAuthenticationOptionsRequest fills PublicKeyCredentialRequestOptions with the previously stored credential records; the server validates the assertion signature using the stored public key and fires OnWebAuthnAuthenticationSuccessful.

Attestation parsing

Supports none, packed, fido-u2f, tpm, android-key, android-safetynet and apple attestation statement formats.

Counter validation

Tracks the per-credential signCount to detect cloned authenticators. If the counter regresses, OnWebAuthnAuthenticationError reports an error you can act on.

User verification

UserVerification can be set to required, preferred or discouraged per ceremony — the validation step enforces the choice.

Credential records

OnWebAuthnAuthenticationOptionsRequest hands you the request so you return the right CredentialRecords for the allowCredentials list of the in-progress login. Storage is yours to design.

Specifications & references

Authoritative sources for the standards this component implements.

Passkeys, the way users expect them

A passkey is a discoverable WebAuthn credential kept by Windows Hello, iCloud Keychain, Google Password Manager or a security key. The server supports the full passkey experience while the credentials stay in your own database.

Usernameless sign-in

Request the authentication options without a user name. The browser lists the passkeys it holds for your site, the user picks one, and the server checks the returned userHandle.

Passkey autofill

With conditional mediation the passkeys appear in the autofill list of the user name field. Add autocomplete="username webauthn" and call startAuthentication(options, true) from /sgcWebAuthn.js.

Several passkeys per user

Register one passkey on the laptop and another on the phone. All the passkeys of an account share one user handle and the authentication options list every one of them.

Synced or device-bound

BackupEligible and BackupState in the credential record tell a synced passkey from a device-bound security key, so you can suggest a second passkey to users with only one device.

Your own database

Save the record in OnWebAuthnRegistrationSuccessful, look up the credential of a usernameless or autofill sign-in in OnWebAuthnAuthenticationGetCredential, and store the new counter in OnWebAuthnAuthenticationSuccessful.

Cloned authenticator detection

A signature counter that does not move forward is rejected as a possible clone, and so is a backup eligibility flag that changes between sign-ins. Synced passkeys that always report 0 keep working.

Read Passkeys in Delphi: Passwordless Login With WebAuthn and the Passkeys help topic.

Documentation & Demos

Deep-link to the component reference, grab the ready-to-run demo project, and download the trial.

Online Help — TsgcWSAPIServer_WebAuthn Full property, method and event reference for this component.
Demo Project — Demos\20.HTTP_Protocol\12.WebAuthn Ready-to-run example project. Ships inside the sgcWebSockets package — download the trial below.
Technical Document (PDF) Features, quick start, code samples for Delphi & C++ Builder and primary-source references — this component only.
User Manual (PDF) Comprehensive manual covering every component in the library.
Best value: All-AccessEvery eSeGeCe product, Premium Support included, from €1,059/year.
See All-Access pricing

Ready to Add Passkey Authentication?

Download the free trial and bring WebAuthn / FIDO2 passkeys to your Delphi server.