Phishing-resistant approval
WebAuthn uses public-key cryptography and binds approval to the registered relying party. The legitimate service does not receive the authenticator's private key material.
Real security still depends on the platform, authenticator, user verification and recovery path. A passkey button is not a complete identity model.
