Credential ๐Ÿงช๐Ÿ”—

Description๐Ÿ”—

Portal to request web credentials.

Interface: org.freedesktop.portal.experimental.Credential

Version: Experimental ๐Ÿงช

The Credential portal allows applications to request web credentials. The user will be prompted to select a credential, which the application can use to authenticate. The design of this portal is highly inspired by the W3C Credential Management API and the related credential type specifications.

Currently the only supported credential type is WebAuthn credentials.

Credentials are created by org.freedesktop.portal.experimental.Credential.CreateCredential and retrieved by org.freedesktop.portal.experimental.Credential.GetCredential.

The D-Bus interface for the Credential portal is available under the bus name org.freedesktop.portal.Desktop and the object path /org/freedesktop/portal/desktop.

Properties๐Ÿ”—

org.freedesktop.portal.experimental.Credential:ConditionalCreate๐Ÿ”—

ConditionalCreate readable b

Whether conditional mediation is supported for credential registration.

org.freedesktop.portal.experimental.Credential:ConditionalGet๐Ÿ”—

ConditionalGet readable b

Whether conditional mediation is supported for authentication.

org.freedesktop.portal.experimental.Credential:HybridTransport๐Ÿ”—

HybridTransport readable b

Whether hybrid authenticators are supported.

org.freedesktop.portal.experimental.Credential:PasskeyPlatformAuthenticator๐Ÿ”—

PasskeyPlatformAuthenticator readable b

Whether a passkey platform authenticator (local or via hybrid transport) is accessible via this API.

org.freedesktop.portal.experimental.Credential:UserVerifyingPlatformAuthenticator๐Ÿ”—

UserVerifyingPlatformAuthenticator readable b

Whether a user-verifying platform authenticator is available via this API.

org.freedesktop.portal.experimental.Credential:RelatedOrigins๐Ÿ”—

RelatedOrigins readable b

Whether matching origins using WebAuthn Related Origin Requests is supported.

org.freedesktop.portal.experimental.Credential:SignalAllAcceptedCredentials๐Ÿ”—

SignalAllAcceptedCredentials readable b

Whether WebAuthn signalAllAcceptedCredentials() is supported.

org.freedesktop.portal.experimental.Credential:SignalCurrentUserDetails๐Ÿ”—

SignalCurrentUserDetails readable b

Whether WebAuthn signalCurrentUserDetails() is supported.

org.freedesktop.portal.experimental.Credential:SignalUnknownCredential๐Ÿ”—

SignalUnknownCredential readable b

The WebAuthn Client supports signalUnknownCredential().

org.freedesktop.portal.experimental.Credential:version๐Ÿ”—

version readable u

Methods๐Ÿ”—

org.freedesktop.portal.experimental.Credential.CreateCredential๐Ÿ”—

CreateCredential (
  IN parent_window s,
  IN origin s,
  IN type s,
  IN options a{sv},
  OUT handle o
)

Requests a new credential to be stored.

Supported keys in the options vardict include:

  • activation_token (s)

    A token that can be used to activate the credential selection dialog.

  • handle_token (s)

    A string that will be used as the last element of the handle. Must be a valid object path element. See the Request documentation for more information about the handle.

  • public_key (s):

    A string of JSON that corresponds to the WebAuthn PublicKeyCredentialCreationOptions type. Required if type is publicKey.

  • top_origin (s)

    The top-level origin of the client window for cross-origin requests. Optional. Omit to denote a same-origin request.

The following results get returned via the org.freedesktop.portal.Request::Response signal:

  • type (s)

    Type of the created credential. Currently, publicKey is the only supported type.

  • registration_response_json (s)

    If type is publicKey, a string of JSON that corresonds to the WebAuthn PublicKeyCredential type with the response field set as an AuthenticatorAttestationResponse.

parent_window

Identifier for the application window, see Window Identifiers.

origin

The origin of the request. Must be a valid HTTPS origin.

type

Type of the created credential. Currently, publicKey is the only supported type.

options

The credential request context and parameters.

handle

Object path for the Request object representing this call

org.freedesktop.portal.experimental.Credential.GetCredential๐Ÿ”—

GetCredential (
  IN parent_window s,
  IN origin s,
  IN options a{sv},
  OUT handle o
)

Returns a credential.

Note

Parameters for at least one credential request type must be included in options. In future versions, multiple credential types may be requested in one call to GetCredential(), though there is currently only one supported type: public_key. The type key of the response denotes which type of credential was selected by the user and returned.

Supported keys in the options vardict include:

  • activation_token (s)

    A token that can be used to activate the credential selection dialog.

  • handle_token (s)

    A string that will be used as the last element of the handle. Must be a valid object path element. See the Request documentation for more information about the handle.

  • public_key (a{sv})

    A dictionary that contains a field request_json, which is a string of JSON that corresponds to the WebAuthn PublicKeyCredentialRequestOptions type.

  • top_origin (s)

    The top-level origin of the client window for cross-origin requests. Pass an empty string to denote a same-origin request.

The following results get returned via the org.freedesktop.portal.Request::Response signal:

  • type (s)

    Type of the returned credential. Currently, publicKey is the only supported type.

  • authentication_response_json (s)

    If type is publicKey, a string of JSON that corresonds to the WebAuthn PublicKeyCredential type with the response field set as an AuthenticatorAssertionResponse.

parent_window

Identifier for the application window, see Window Identifiers

origin

The origin of the request. Must be a valid HTTPS origin.

options

The credential request context and parameters.

handle

Object path for the Request object representing this call