- Related origins are verified by browsers against - {{ wellKnownUrl }} - — served automatically when this instance hosts {{ dialog.data.rp_id }}; otherwise publish this document there: -
-{{ wellKnownJson }}
-
- {{ dialog.data.message }}
++ Related origins are verified by browsers against + {{ wellKnownUrl }} + — served automatically when this instance hosts {{ dialog.data.rp_id }}; otherwise publish this document there: +
+{{ wellKnownJson }}
+
+ The domain name passkeys belong to — they work on this domain and its subdomains, and related domains. Cannot be changed later.
+ + + ++ Only the listed sites may sign in with {{ dialog.data.rp_id }} passkeys. Wildcards may be used: **.{{ dialog.data.rp_id }} allows the whole domain, *.{{ dialog.data.rp_id }} only a single subdomain level. 🔗 means related host requiring WebAuthn ROR setup. 🔑 is the dedicated Paskia host for all account management. +
+E.g. yourapp:reports. Changing the scope name may break deployed applications.
+ +A domain restricts this permission to that host (any configured domain's rp-id or a subdomain of it). An OIDC client UUID sends it as a groups claim to that client.
+Role: {{ dialog.data.role.display_name }}
+ +