I am rather new to privacyidea (using 3.12.1). is it possible to use passkeys as second factor to authenticate to the privacyidea webui? I successfully use PUSH, TOTP, yubikey (OTP) tokens to authenticate to the webui. I also have successfully enrolled passkey tokens (I can test them in the token view in the webui successfully) but I see no way to use them when logging in to the webui.
to answer my own question: I was apparently blind and did not see the “passkey login” button on the login screen. using that, authentication worked perfectly
one thing: after authenticating, the webui still shows the login screen, instead of redirecting to the token view. this happens when logging in with user/password/push for example.
However, I can not reproduce this behaviour for now. Did you check that the authentication was successful (e.g. browser tools / privacyidea log)? Do you have any further webui or user policies that could influence the login behaviour?
yes, the authentication was successful, I could change manually to the token view. This behavior was consistent, i.e. I could repeat it 3 times (logging out and in again). However, I just retried, and now it works as expected.