⚠ SCOPE: Credential crypto-suite migration ONLY. Checks COSE algorithm IDs and CTAP version for PQC conformance. Does NOT cover credential format or protocol conformance (EUDI scope).
ART-88 · Wave 18 · Post-Quantum Cryptography · FIDO2/WebAuthn

FIDO2 / WebAuthn PQC Conformance Checker

Validates FIDO2/WebAuthn authenticator support for ML-DSA (FIDO Alliance CTAP2.3) vs IANA COSE algorithm registry. Checks COSE identifier presence and CTAP version. Scoped to credential crypto-suite migration — not credential FORMAT/protocol conformance (EUDI scope).

FIDO CTAP2.3 IANA COSE Registry NOT EUDI credential format
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Authenticator Configuration
PQC Target
Mode
CTAP Version
PQC COSE IDs
Conformance Checks
PQC COSE Algorithms Found
Flags
References: IANA COSE Algorithms Registry — ML-DSA COSE IDs (verify current IANA assignments) · FIDO Alliance CTAP2.3 specification — minimum version for native PQC (verify current). DECISION-SUPPORT DRAFT — not a FIDO certification.
OpenChainGraph v0.4 artifact · execution_hash:

  

Ask your agent

Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.

Run the AINumbers MCP tool `check_fido_pqc_conformance`. Task: Validate FIDO2/WebAuthn authenticator ML-DSA conformance vs IANA COSE algorithm registry identifiers and CTAP2.3 minimum version.
Call it with arguments: {"policy_parameters":{}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-88-fido-pqc-conformance-checker.html#p=v1.H4sIAAAAAAAA_wECAP3_e31Dv6ajAgAAAA