Skip to content
CAI
Software that uses CAICheck a score

liveshowy/webauthn_components

56.3

Adequate · 18 September 2026

1.1k

lines of production code

Elixir

with TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a beta-stage Elixir library providing modular Phoenix LiveView components for WebAuthn passkey authentication and registration. It enables developers to integrate passwordless sign-up and sign-in flows directly into their applications by handling browser capability detection, challenge management, and session token operations. The library includes dedicated client-side TypeScript hooks and server-side LiveComponents to manage the complete passkey lifecycle, supported by comprehensive test infrastructure for verifying component behavior.

Features

Add WebAuthn passkey authentication and registration hooks

New TypeScript hooks have been added to the client-side static assets to support WebAuthn passkey flows. The AuthenticationHook handles passkey login challenges, including conditional UI autofill detection via the new browser\_supports\_passkey\_autofill utility. The RegistrationHook manages new passkey creation, verifying platform authenticator availability before proceeding. A ClientCapabilitiesHook detects and reports browser capabilities to the server. These components work together to enable secure, passwordless authentication and registration directly in the browser.

priv · high confidence

Introduce dedicated WebAuthn LiveComponents for registration and authentication

This change introduces a new set of Phoenix LiveComponents (\RegistrationComponent\, \AuthenticationComponent\, \ClientCapabilitiesComponent\) to handle WebAuthn passkey flows. Users can now integrate passkey sign-up and sign-in directly into their LiveViews, with automatic detection of browser capabilities to enable or disable buttons appropriately. The components support platform and cross-platform authenticators, optional user-verifying platform authenticator checks, and passkey autofill. A new \Credential\ struct replaces the previous \WebauthnUser\ for user data, and a custom \CoseKey\ Ecto type is provided for storing public keys.

_lib/webauthn\components · high confidence

Removals

Removal of stub WebauthnLiveComponent module

The placeholder \WebauthnLiveComponent\ module, which previously only contained a stub \hello/0\ function, has been removed from the library. This eliminates unused boilerplate code from the public API surface.

lib · high confidence

Behavioural changes

Initial configuration for WebAuthn components and test environment logging

The application now includes a base configuration file that sets Jason as the JSON library and defines specific settings for the WebAuthn test endpoint, including its network address, secret key, and LiveView signing salt. Additionally, when running in the test environment, the logger level is explicitly set to :warning to reduce output noise during testing.

config · high confidence

WebauthnComponents v0.10: Passkey Authentication for Phoenix LiveView

The package has been renamed from \webauthn\_live\_component\ to \webauthn\_components\ (v0.10) and now provides modular components for passkey registration, authentication, and session token management in Phoenix LiveView applications. The previous \wac.install\ code generator has been removed, requiring developers to manually integrate the components into their own data models and LiveViews. The project is currently in beta status and requires Elixir 1.20.2 and Erlang/OTP 28.4.

(repo-wide) · high confidence

Test coverage

Added test coverage for WebAuthn UI components; Added test support infrastructure for WebAuthn component testing; Updated test configuration and removed stub test.

Dependencies

Upgrade to Phoenix LiveView 1.2 and Elixir 1.18

The library has been updated to require Elixir 1.18 and Phoenix LiveView 1.2, ensuring compatibility with the latest Phoenix ecosystem features. This release also introduces several new dependencies, including \wax\_\ for cryptographic operations, \lazy\_html\ for testing, and \live\_isolated\_component\ for isolated component testing, while upgrading core libraries like Ecto, Phoenix, and ExDoc to their latest versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 56.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 69
  • Readiness 35
  • Security 98

Changes since last survey

  • 86 commits — 74 feature/other, 12 fixes

By area

  • (root) — 52 commits
  • lib/webauthn_components — 9 commits
  • lib/wac_gen — 6 commits
  • .github/ISSUE_TEMPLATE — 5 commits
  • priv/static — 3 commits
  • templates/components — 2 commits
  • test/webauthn_components — 2 commits
  • .github/pull_request_template.md — 1 commit
  • .github/workflows — 1 commit
  • config/config.exs — 1 commit
  • templates/contexts — 1 commit
  • templates/controllers — 1 commit
  • templates/schemas — 1 commit
  • templates/session_hooks — 1 commit

Notable commits

  • fix: 31 fix passkey hook js (#32)
  • fix: 54 - Fix RP Configuration (#55)
  • fix: Fix button text (#40)
  • fix: Fix incorrect function spec (#77)
  • fix: Fixes (#17)
  • fix: Fixes (#43)
  • fix: add alias to RequireUser hook to fix dialyzer "Unknown type" warning (#58)
  • fix: fix errors
  • fix: fix gh template project number
  • fix: fix project tags
  • fix: fix repo alias pattern match
  • fix: fix token query
  • change: #6 add js hooks (#14)
  • change: 15 Schema Generators (#49)
  • change: 25 add passkey button (#27)
  • change: 26 support resident keys (#30)
  • change: 34 split registration and authentication (#37)
  • change: 42 Improve Token Security & Extend wac.install (#50)
  • change: 76 Separate Authentication & Registration Views (#79)
  • change: Accept User Details (#45)
  • …and 66 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

liveshowy/webauthn_components was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cea0e1f624d0a119d49f15337b96649b398b3d9f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.