⚠ SCOPE: Credential crypto-suite migration ONLY. Checks COSE algorithm IDs and CTAP version for PQC conformance. Does NOT cover credential format or protocol conformance (EUDI scope).
ART-88 · Wave 18 · Post-Quantum Cryptography · FIDO2/WebAuthn
FIDO2 / WebAuthn PQC Conformance Checker
Validates FIDO2/WebAuthn authenticator support for ML-DSA (FIDO Alliance CTAP2.3) vs IANA COSE algorithm registry. Checks COSE identifier presence and CTAP version. Scoped to credential crypto-suite migration — not credential FORMAT/protocol conformance (EUDI scope).
FIDO CTAP2.3
IANA COSE Registry
NOT EUDI credential format
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Preset A — Legacy only (ES256+RS256, CTAP 2.0): NOT CONFORMANT
Preset B — Hybrid (ES256+ML-DSA-65, CTAP 2.3): CONFORMANT hybrid
Preset C — Full PQC (ML-DSA-65 only, CTAP 2.3): CONFORMANT pqc_only
Authenticator Configuration
Attestation format
packed
tpm
fido-u2f
none
CTAP version
2.0
2.1
2.2
2.3
PQC Target
Target PQC algorithm
ML-DSA-44 (COSE -48)
ML-DSA-65 (COSE -49)
ML-DSA-87 (COSE -50)
Check PQC Conformance →
Conformance Checks
PQC COSE Algorithms Found
–
Flags
–
References: IANA COSE Algorithms Registry — ML-DSA COSE IDs (verify current IANA assignments) · FIDO Alliance CTAP2.3 specification — minimum version for native PQC (verify current). DECISION-SUPPORT DRAFT — not a FIDO certification.
⬇ Export AP2 JSON
⬇ Sign artifact (Ed25519 · §16)
🔏 Verify signature (§16)
OpenChainGraph v0.4 artifact · execution_hash:
–
{ } MCP manifest