Credential ๐งช๐
Description๐
Portal to request web credentials.
Interface: org.freedesktop.portal.experimental.Credential
Version: Experimental ๐งช
The Credential portal allows applications to request web credentials. The user will be prompted to select a credential, which the application can use to authenticate. The design of this portal is highly inspired by the W3C Credential Management API and the related credential type specifications.
Currently the only supported credential type is WebAuthn credentials.
Credentials are created by org.freedesktop.portal.experimental.Credential.CreateCredential and retrieved by org.freedesktop.portal.experimental.Credential.GetCredential.
The D-Bus interface for the Credential portal is available
under the bus name org.freedesktop.portal.Desktop and the
object path /org/freedesktop/portal/desktop.
Properties๐
org.freedesktop.portal.experimental.Credential:ConditionalCreate๐
ConditionalCreate readable b
Whether conditional mediation is supported for credential registration.
org.freedesktop.portal.experimental.Credential:ConditionalGet๐
ConditionalGet readable b
Whether conditional mediation is supported for authentication.
org.freedesktop.portal.experimental.Credential:HybridTransport๐
HybridTransport readable b
Whether hybrid authenticators are supported.
org.freedesktop.portal.experimental.Credential:PasskeyPlatformAuthenticator๐
PasskeyPlatformAuthenticator readable b
Whether a passkey platform authenticator (local or via hybrid transport) is accessible via this API.
org.freedesktop.portal.experimental.Credential:UserVerifyingPlatformAuthenticator๐
UserVerifyingPlatformAuthenticator readable b
Whether a user-verifying platform authenticator is available via this API.
org.freedesktop.portal.experimental.Credential:SignalAllAcceptedCredentials๐
SignalAllAcceptedCredentials readable b
Whether WebAuthn signalAllAcceptedCredentials() is supported.
org.freedesktop.portal.experimental.Credential:SignalCurrentUserDetails๐
SignalCurrentUserDetails readable b
Whether WebAuthn signalCurrentUserDetails() is supported.
org.freedesktop.portal.experimental.Credential:SignalUnknownCredential๐
SignalUnknownCredential readable b
The WebAuthn Client supports signalUnknownCredential().
org.freedesktop.portal.experimental.Credential:version๐
version readable u
Methods๐
org.freedesktop.portal.experimental.Credential.CreateCredential๐
CreateCredential (
IN parent_window s,
IN origin s,
IN type s,
IN options a{sv},
OUT handle o
)
Requests a new credential to be stored.
Supported keys in the options vardict include:
activation_token(s)A token that can be used to activate the credential selection dialog.
handle_token(s)A string that will be used as the last element of the
handle. Must be a valid object path element. See the Request documentation for more information about thehandle.public_key(s):A string of JSON that corresponds to the WebAuthn PublicKeyCredentialCreationOptions type. Required if
typeispublicKey.top_origin(s)The top-level origin of the client window for cross-origin requests. Optional. Omit to denote a same-origin request.
The following results get returned via the org.freedesktop.portal.Request::Response signal:
type(s)Type of the created credential. Currently,
publicKeyis the only supported type.registration_response_json(s)If
typeispublicKey, a string of JSON that corresonds to the WebAuthn PublicKeyCredential type with theresponsefield set as an AuthenticatorAttestationResponse.
- parent_window
Identifier for the application window, see Window Identifiers.
- origin
The origin of the request. Must be a valid HTTPS origin.
- type
Type of the created credential. Currently,
publicKeyis the only supported type.- options
The credential request context and parameters.
- handle
Object path for the Request object representing this call
org.freedesktop.portal.experimental.Credential.GetCredential๐
GetCredential (
IN parent_window s,
IN origin s,
IN options a{sv},
OUT handle o
)
Returns a credential.
Note
Parameters for at least one credential request type must be included
in options. In future versions, multiple credential types may be
requested in one call to GetCredential(), though there is currently
only one supported type: public_key. The type key of the
response denotes which type of credential was selected by the user
and returned.
Supported keys in the options vardict include:
activation_token(s)A token that can be used to activate the credential selection dialog.
handle_token(s)A string that will be used as the last element of the
handle. Must be a valid object path element. See the Request documentation for more information about thehandle.public_key(a{sv})A dictionary that contains a field
request_json, which is a string of JSON that corresponds to the WebAuthn PublicKeyCredentialRequestOptions type.top_origin(s)The top-level origin of the client window for cross-origin requests. Pass an empty string to denote a same-origin request.
The following results get returned via the org.freedesktop.portal.Request::Response signal:
type(s)Type of the returned credential. Currently,
publicKeyis the only supported type.authentication_response_json(s)If
typeispublicKey, a string of JSON that corresonds to the WebAuthn PublicKeyCredential type with theresponsefield set as an AuthenticatorAssertionResponse.
- parent_window
Identifier for the application window, see Window Identifiers
- origin
The origin of the request. Must be a valid HTTPS origin.
- options
The credential request context and parameters.
- handle
Object path for the Request object representing this call