WebAuthn with Go
  • Go 66.7%
  • TypeScript 22.8%
  • HTML 8%
  • JavaScript 2%
  • Dockerfile 0.3%
  • Other 0.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Ralph Schaer 0b0d864394 upgrade
2026-10-04 10:09:15 +02:00
client upgrade 2026-10-04 10:09:15 +02:00
server upgrade 2026-10-04 10:09:15 +02:00
.gitignore initial commit 2023-01-22 19:18:52 +01:00
LICENSE Initial commit 2022-11-26 09:47:16 +01:00
README.md Harden WebAuthn flows and deployment configuration 2026-09-03 20:28:46 +02:00

WebAuthn demo with Go

A passkey registration and authentication example with a Go API, PostgreSQL, and an Angular client. It accompanies the original blog post.

Run locally

Prerequisites: Go, Node.js/npm, Docker, and Docker Compose.

  1. Start PostgreSQL:

    cd server
    docker compose up -d
    
  2. Apply the database migration and start the API:

    go run ./cmd/migrate up
    go run ./cmd/api
    
  3. In another terminal, install and start the client:

    cd client
    npm install
    npm start
    

Open http://localhost:4200. The development server proxies /api/v1 to the API at 127.0.0.1:8080.

Configuration

The API reads server/app.yml. Values can be overridden with environment variables using the WEBAUTHN_ prefix and underscores for nesting. For example, WEBAUTHN_DB_HOST=db:5432 overrides db.host.

For production, serve the client and proxy /api/v1 to the Go API on the same origin, then update webauthn.rpId and webauthn.rpOrigins to match that origin. Secure session cookies are enabled by default outside the checked-in development configuration.

Checks

cd server
go test ./...
go vet ./...

cd ../client
npm run lint
npm run build
npm audit