Implement WebAuthn attestation verification with packed format using FIDO MDS3 trust anchors

domain: fidoalliance.org · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Download the MDS3 BLOB from https://mds3.fidoalliance.org/ and verify the JWT signature against the GlobalSign R3 root certificate
  2. Parse the BLOB payload to build a map of AAGUID to metadata entries containing attestation root certificates
  3. During registration, extract the AAGUID from the authenticator data and look up its metadata entry in the MDS3 map
  4. For packed attestation, verify the x5c leaf certificate chains up to the MDS3-provided root; for self attestation, verify the public key in the credential matches the signature key
  5. Check the metadata entry's statusReports for FIDO_CERTIFIED or equivalent; reject authenticators with USER_VERIFICATION_BYPASS or ATTESTATION_KEY_COMPROMISE statuses
  6. Cache the MDS3 BLOB with its nextUpdate field; refresh before expiry to stay current with revocations

Known gotchas

Related routes

Use AAGUID to look up authenticator metadata in FIDO MDS3 and enforce authenticator policy
fidoalliance.org · 5 steps · unrated
Distinguish and configure platform vs cross-platform authenticator attachment in WebAuthn
w3.org · 5 steps · unrated
Implement WebAuthn registration and authentication ceremonies server-side, including attestation and assertion verification, per the current W3C spec
w3.org/TR/webauthn-3 · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans