Support in current browsers

Checked against the current browser versions recorded in MDN browser data 8.0.7.

BrowserMinimumOutcomeReason
Chrome150WorksEvery required mapped BCD feature is available without a recorded qualification.
Edge150WorksEvery required mapped BCD feature is available without a recorded qualification.
Firefox152WorksEvery required mapped BCD feature is available without a recorded qualification.
Safari26.5Not supportedAt least one required mapped feature is not available at this browser baseline.
Chrome for Android150WorksEvery required mapped BCD feature is available without a recorded qualification.
Firefox for Android152Not supportedAt least one required mapped feature is not available at this browser baseline.
Safari on iOS26.5Not supportedAt least one required mapped feature is not available at this browser baseline.
Android WebView150Not supportedAt least one required mapped feature is not available at this browser baseline.
Samsung Internet29.0WorksEvery required mapped BCD feature is available without a recorded qualification.

What this feature can and cannot do

Helps protect against

  • Exportable application key material
  • Password-derived local secrets

Does not guarantee

  • Account recovery
  • Relying-party verification
  • Every authenticator

What you need before using it

  • A compatible authenticator
  • A reviewed WebAuthn extension design

Fallback to keep in place

Keep key derivation and recovery independent of the extension where it is unavailable.