PasskeyBridge
™
Solutions
Pricing
Developers
Docs
Guides & API reference
SDK
Client SDK & install
API Playground
Fire live requests
Changelog
What shipped, when
Status
Live system health
Security
Blog
Sign in
Start free
FAQ
Frequently Asked Questions
149 real questions. Real answers. No filler.
Last reviewed:
June 8, 2026
General
What is PasskeyBridge?
Who is PasskeyBridge for?
Is PasskeyBridge a replacement for my auth provider?
What does 'patent-pending' mean for PasskeyBridge?
What is the 'identity trust layer' architecture?
Three Pillars
What is Pillar I: Network Attestation?
What is Pillar II: Legal Identity Verification?
What is Pillar III: Biometric Binding?
Do I need all three pillars?
Technical—Signal Ingestion
How does signal ingestion work?
What signal sources do you support?
What signal types can I detect?
How do I authenticate ingest requests?
Technical—Playbooks & Actions
What is a playbook?
What action types are supported?
How does webhook callback signing work?
What happens if a webhook callback fails?
Do you offer pre-built playbook templates?
Technical—Verifiable Credentials (Pillar II)
Does PasskeyBridge have its own VC engine?
What VC formats and standards are supported?
What are trusted issuer registries?
What credential types can I issue and accept?
How does zero-PII work with Verifiable Credentials?
Is there a client-side SDK for credential management?
What is W3C StatusList2021 and how does PasskeyBridge implement it?
What is batch VP Token verification?
How does StatusList2021 auto-refresh work?
Does the SDK store credentials on the server?
Technical—Biometric Binding (Pillar III)
How does WebAuthn passkey registration work?
What devices support passkey authentication?
Can users register multiple passkeys?
What is 'biometric binding' in the context of the three-pillar model?
Agentic Identity & Trust Scoring
What are agent delegates?
What is Graduated Agentic Trust Scoring (NF-05)?
How does dynamic scope narrowing work?
Does the AI influence trust decisions?
Why do I need agent delegates?
A2A Horizontal Trust Protocol
What is the A2A Horizontal Trust Protocol?
How does A2A trust negotiation work?
What is the Combined Trust Coefficient?
How are A2A handshakes cryptographically protected?
What happens when a carrier signal invalidates an A2A negotiation?
Observability, Alerting & HITL Review
What observability capabilities does PasskeyBridge provide?
How do alert rules work?
What is Human-in-the-Loop (HITL) review?
What is behavioral clustering?
Can I integrate PasskeyBridge metrics with my existing monitoring stack?
mTLS Agent Certificates & Key Rotation
What are mTLS agent certificates?
How does automated key rotation work?
What resource types support automated rotation?
Spatial Binding & Atomic Fingerprints (NF-08)
What is Spatially-Bound Identity Attestation?
What sensor channels does the client SDK capture?
What verticals does NF-08 target?
How does the ≤100ms temporal window work?
How is NF-08 different from TPM or Secure Enclave attestation?
Quantum Resilience (PQC)
What is Quantum-Ready PQC?
What NIST standards does PasskeyBridge follow for PQC?
What is the quantum entropy system?
Do I need to change my integration for PQC?
Why is PQC Enterprise-only?
What is the difference between ML-DSA-65 and ML-DSA-87?
Enterprise SSO & SCIM
Does PasskeyBridge support SAML and OIDC SSO?
What is SCIM provisioning?
How does the Okta integration work?
Can I scope API keys for SCIM and Okta?
What is Okta Identity Security Posture Management (ISPM)?
What is Entra ID Identity Security Posture Management (ISPM)?
What is Google Workspace Identity Security Posture Management (ISPM)?
What is AWS IAM Identity Center Identity Security Posture Management (ISPM)?
What is PingOne Identity Security Posture Management (ISPM)?
What is CyberArk Identity Security Posture Management (ISPM)?
What is OneLogin Identity Security Posture Management (ISPM)?
Can I audit all seven identity providers simultaneously?
Supply Chain Provenance
What is Supply Chain Provenance Guard?
What SLSA levels does PasskeyBridge support?
What is SBOM signing?
SDK Integrity Attestation
What is SDK Integrity Attestation?
What are the six integrity checks?
How does SDK Integrity protect against EvilGinx2?
Breakglass Emergency Access
What is the Breakglass Emergency Access Protocol?
How does multi-party approval work?
What access scopes are available for breakglass sessions?
Cross-Tenant Threat Sharing
What is Cross-Tenant Threat Sharing?
How does k-anonymity protect tenant privacy?
What indicator types are supported?
Is participation mandatory?
Insider Threat Analytics
What is Insider Threat Behavioral Analytics?
How does agent insider threat detection work?
What data does the insider threat engine analyze?
Can detection thresholds be customized?
SSF/CAEP & DPoP
What is SSF/CAEP?
How does PasskeyBridge use SSF/CAEP?
What is DPoP (Demonstrating Proof of Possession)?
What is DPoP shadow mode?
What signing algorithms does DPoP support?
Operational Resilience
How does PasskeyBridge prevent runaway tenants from impacting the platform?
How does PasskeyBridge protect itself from SSRF and arbitrary outbound calls?
What is the Anomaly Scanner?
What is the Canary Mesh?
How does PasskeyBridge deliver webhooks reliably without head-of-line blocking?
Where can customers see real-time platform health?
How do tenant signing keys rotate without breaking integrations?
What happens if a stale browser bundle is loaded after a deploy?
Enterprise Features
What is the Shadow Identity Proxy?
What is the Cached Proof System?
What is Deterministic Cross-Reference?
What is the BLAST protocol?
Can I use Enterprise features on the Pro plan?
AI Intelligence Layer
What is the AI Intelligence Layer?
Does the Intelligence Layer affect ingest latency?
What is the hallucination guard?
Is my signal data sent to a third-party AI?
Is the Intelligence Layer available on all plans?
Social Recovery
What is social recovery?
How do I set up social recovery?
What happens to agent delegates during recovery?
Security & Privacy
Does PasskeyBridge store personal data?
How are API keys secured?
What is PasskeyBridge's SOC 2 posture?
How is tenant data isolated?
What happens if PasskeyBridge itself is compromised?
What is the Bulk PII Migration tooling?
Sign-in & Federated Auth
How do I sign into the PasskeyBridge dashboard?
How does Continue with Google work?
How does Continue with Microsoft (SSO) work?
What does my IT admin have to do to enable Microsoft SSO?
Is Continue with Microsoft the same as the Entra ID ISPM module?
Are Google sign-in and Microsoft SSO available on every plan?
Developers & SDK
Is there a public SDK I can install from npm?
Can I try the API without signing up?
How do I request SOC 2 evidence?
What is the public status page and how is it produced?
Pricing & Billing
Is there a free tier?
What happens if I exceed my signal limit?
How is overage reconciled at the end of the billing period?
How does Pillar II / III licensing work?
Can I switch plans?
Integration & Onboarding
How long does integration take?
How do I track my onboarding progress across the wizards?
Where do I manage teammates and roles inside my organization?
How do I open a support ticket without leaving the dashboard?
Will I get notified when something happens in my tenant?
Can I export my own organization's audit log for SOC 2 evidence?
Do you have an API reference?
Can I test without a real carrier webhook?
What data formats do you accept?
Legal & IP
Is PasskeyBridge patented?
Where is PasskeyBridge incorporated?
What are your data retention policies?
PasskeyBridge