Resources · 111
Passkeys: prepare a domain and RP ID change
Separate business account, web origin and RP ID to plan a transition without silently rebinding credentials.
· 2 min
What this guide helps achieve
- Map domains and accounts
- Test registration and rejection
- Plan transition and rollback
Quick check
- Origin, RP ID, account and journey matrix.
- Expected outcomes and rejection evidence.
- Transition plan and recovery exercise.
Step-by-step method
- 01
Map domains and accounts
Record old and new origins, RP IDs and associated accounts. An identical account name does not make a passkey valid for a different RP ID. Check WebAuthn’s allowed combinations and the access paths remaining available during transition.
Origin, RP ID, account and journey matrix.
- 02
Test registration and rejection
In an authorised test environment, check challenge, origin, RP ID and account binding with a suitable library. Try an unexpected origin and a replayed challenge. If the RP ID changes, prepare authenticated new registration; copying a database record is not key migration.
Expected outcomes and rejection evidence.
- 03
Plan transition and rollback
Test a user with only the old credential, recovery and already open sessions. Define the order for opening and retiring journeys with verified rollback. Successful registration on the new domain does not prove all old sessions have been revoked.
Transition plan and recovery exercise.
Acceptance case to reproduce
Fictional example: these inputs describe no customer or observed result.
View case inputs
{
"old_origin": "https://login.old.example",
"old_rp_id": "old.example",
"new_origin": "https://login.new.example",
"new_rp_id": "new.example",
"same_service_account": true,
"expected": "authenticated_new_registration"
}Expected decision
Fictional example: the account stays the same, but old.example becomes new.example with a different RP ID. The old credential cannot be silently rebound; new registration must follow the planned authenticated journey.
Your acceptance workbook
Record observations against this guide’s criteria. A record is not certification.
The workbook does not save automatically. Export before leaving.
Filters do not limit exports. Actions include issues and unreviewed criteria.
Import replaces current observations after your confirmation.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Checked journeys | Validated cases / defined cases | Include loss, rejection and rollback |
| Access still active | Credentials and sessions in the old scope | Check the retirement decision separately |
Common pitfalls
Frequently asked questions
Can a database edit change a passkey’s RP ID?
No. The RP ID is part of the credential’s verified scope. Prepare valid registration for the new scope and an authenticated account mapping.
Official references
References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.






