Before you begin implementing passkeys on your application, you should first become familiar with the following key terms and concepts:
Passkeys
Passkeys are FIDO-compliant authentication credentials that are tied to a user's account on a website or application. They allow users to access apps and websites the same way they would unlock their mobile devices — using biometrics (face, fingerprint), a PIN, or a pattern.
FIDO
FIDO (Fast Identity Online) is the underlying standard that enables passkeys. It uses cryptographic key pairs — a public key that can be shared with websites or applications, and a private key that remains on the user's device — to make secure, passwordless authentication possible.
JWT
JWTs stand for JSON Web Tokens which are used to securely transmit information between:
your app
your application server, and
the Digipass S3 Authentication Cloud.
The information can be trusted and verified because each token is digitally signed.

The diagram above shows how JWTs facilitate communication during the registration process:1
User sends an ID and password to the application server via an app or browser.
Application server returns a JWT.
A FIDO registration request (including a JWT) is sent to the Digipass S3 Authentication Cloud.
Digipass S3 Authentication Cloud verifies the JWT and performs FIDO registration.
Once the user signs out and decides to login again, a FIDO authentication request is made to the Digipass S3 Authentication Cloud.
If authentication is successful, Digipass S3 Authentication Cloud generates and returns a JWT.
After the application server verifies the JWT, the user can now access additional app resources using the JWT.
Tenant
A tenant is an instance of the Digipass S3 Authentication Cloud that is dedicated to your organization. To maintain security for all users, a unique JWT issuer and signing key is generated for each tenant.
Tutorial App
A simplified application included with the Digipass S3 App SDKs. The source code can be used to demonstrate passkey operations.
The Digipass S3 Tutorial App is a simple client application that is included in all Digipass S3 SDKs to help you learn how to:
Configure your tenant.
Allow an application to access your tenant.
Build and deploy an application.
Connect and test an application.
1 The authentication process has been omitted for simplicity.