如何从谷歌Chrome浏览器中删除WebAuthn驻留密钥/可发现凭证?
问题:删除Chrome中WebAuthn客户端可发现凭证(常驻密钥)
我有一个使用Passkeys/WebAuthn的测试Web应用,注册时设置了requireResidentKey: true,核心代码如下:
const publicKeyCredentialCreationOptions = { challenge: new Uint8Array(base64urldecode(step1.challenge)), rp: step1.relayingPartyInfo, user: { id: new TextEncoder().encode(step1.userInfo.id), name: step1.userInfo.name, displayName: step1.userInfo.displayName, }, pubKeyCredParams: [ { alg: -7, type: "public-key" }, { alg: -257, type: "public-key" }, ], authenticatorSelection: { requireResidentKey: true, }, timeout: 60000, attestation: "direct", }; const credential = await navigator.credentials.create({ publicKey: publicKeyCredentialCreationOptions, });
在Chrome客户端执行这段代码后,注册界面正常弹出且注册成功,返回的PublicKeyCredential对象中authenticatorAttachment值为"platform",.response.clientDataJSON和.response.attestationObject均正常。调用navigator.credentials.get()时,会弹出列表显示测试期间注册的所有可发现公钥。
现需删除这些客户端可发现凭证/常驻密钥,请问能否通过Chrome的UI界面、命令行或API实现?
可行的删除方式
1. Chrome UI界面操作
- 打开Chrome设置,依次进入「隐私和安全」→「密码和表单」→「管理密码」
- 在密码管理页面顶部切换到「Passkeys」标签页
- 找到对应测试应用的凭证条目,点击右侧的三个点按钮,选择「删除」即可单个或批量移除测试生成的可发现凭证
2. 命令行重置(适合自动化测试场景)
Chrome提供命令行参数可重置全部WebAuthn相关数据,注意此操作会清除所有Passkeys/WebAuthn凭证,而非仅测试数据:
- 关闭所有Chrome窗口
- 执行对应系统的命令:
- Windows:
chrome.exe --reset-webauthn - macOS:
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --reset-webauthn - Linux:
google-chrome --reset-webauthn
- Windows:
3. Web API间接处理(需应用配合)
目前WebAuthn标准没有提供直接删除可发现凭证的前端API,但可以通过以下方式间接处理:
- 若能控制测试应用代码,可在注册时记录凭证的
id,后续调用navigator.credentials.preventSilentAccess()阻止该凭证静默登录(但此方法不直接删除凭证) - 若依赖硬件级操作,可使用CTAP2.1的凭证管理命令,但该方式需要硬件支持,且无法通过前端JS直接调用,通常依赖浏览器扩展或系统工具
内容的提问来源于stack exchange,提问作者RubenLaguna
相关产品推荐
相关产品推荐

