Resources · 111

Passkeys: prepare a domain and RP ID change

Separate business account, web origin and RP ID to plan a transition without silently rebinding credentials.

· 2 min

Smartphone and laptop on a table Illustration · fictional scene

What this guide helps achieve

  • Map domains and accounts
  • Test registration and rejection
  • Plan transition and rollback

Quick check

  • Origin, RP ID, account and journey matrix.
  • Expected outcomes and rejection evidence.
  • Transition plan and recovery exercise.

Step-by-step method

  1. 01

    Map domains and accounts

    Record old and new origins, RP IDs and associated accounts. An identical account name does not make a passkey valid for a different RP ID. Check WebAuthn’s allowed combinations and the access paths remaining available during transition.

    Origin, RP ID, account and journey matrix.

  2. 02

    Test registration and rejection

    In an authorised test environment, check challenge, origin, RP ID and account binding with a suitable library. Try an unexpected origin and a replayed challenge. If the RP ID changes, prepare authenticated new registration; copying a database record is not key migration.

    Expected outcomes and rejection evidence.

  3. 03

    Plan transition and rollback

    Test a user with only the old credential, recovery and already open sessions. Define the order for opening and retiring journeys with verified rollback. Successful registration on the new domain does not prove all old sessions have been revoked.

    Transition plan and recovery exercise.

Acceptance case to reproduce

Fictional example: these inputs describe no customer or observed result.

View case inputs
{
    "old_origin": "https://login.old.example",
    "old_rp_id": "old.example",
    "new_origin": "https://login.new.example",
    "new_rp_id": "new.example",
    "same_service_account": true,
    "expected": "authenticated_new_registration"
}

Expected decision

Fictional example: the account stays the same, but old.example becomes new.example with a different RP ID. The old credential cannot be silently rebound; new registration must follow the planned authenticated journey.

W3C — Web Authentication Level 2

Your acceptance workbook

Record observations against this guide’s criteria. A record is not certification.

The workbook does not save automatically. Export before leaving.

Management indicators

IndicatorWhat it measuresFirst action
Checked journeysValidated cases / defined casesInclude loss, rejection and rollback
Access still activeCredentials and sessions in the old scopeCheck the retirement decision separately

Common pitfalls

    Frequently asked questions

    Can a database edit change a passkey’s RP ID?

    No. The RP ID is part of the credential’s verified scope. Prepare valid registration for the new scope and an authenticated account mapping.

    Official references

    References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.