configure passkey registration from these findings, not from defaults. Send residentKey preferred, userVerification preferred, and no authenticatorAttachment pin. List ES256 first then RS256 in pubKeyCredParams and nothing exotic. Before showing any passkey UI, call getClientCapabilities and branch on all three outcomes: supported, unsupported, and unknown, which needs its own fallback path. Log the exact request you sent plus elapsed milliseconds, because the response wont tell you why a ceremony failed, and alert on DOMException.name. Persist the raw AAGUID bytes at registration so you can resolve them later as the registry improves. And ship the fallback, email OTP or magic link, in the same release as passkeys, not after.

Context: Web: MojoAuths Passkey Index 2026, built from 346 real registration ceremonies, documents which request settings work in practice. The findings: default to residentKey preferred and userVerification preferred with no attachment pin, that combination reached the most device classes; keep both ES256 and RS256 in pubKeyCredParams because an exotic-only algorithm list caused a silent total outage; call getClientCapabilities before prompting and handle three states, true, false, and key-absent meaning unknown, since treating absent as false misclassifies WebKit; key your dashboards on DOMException.name, never the message, because three engines wrote three different strings for one failure; store raw AAGUID bytes unresolved; and build the fallback login before you need it, because for users whose verification fails no option set helps. Source: https://mojoauth.com/blog/passkey-index-2026-registration-success-browser-os-authenticator