hackernews • r/hackernews
Comment on: Passkey Implementation: Misconceptions, pitfalls and unknown unknowns
> However most implementations take the result of a passkey login and issue a session token so…Is there a way to avoid this and use token for every request in real world?I mean, that’s an interesting idea, but I think it’s not going to work in practice (can’t make user show face or touch a token on every request). Please let me know if I’m wrong here!