BE and BS Flags Explained: Telling a Synced Passkey from a Device-Bound One
ID: e720f774-edc4-54b8-b156-8b91ec81d2b5
STIX ID: report--e720f774-edc4-54b8-b156-8b91ec81d2b5
Feed Name: Security Boulevard
Date Published: 2026-07-16
Date Updated: 2026-07-16
Author: MojoAuth Blog - Passwordless Authentication & Identity Solutions
This article explains the WebAuthn BE (Backup Eligibility) and BS (Backup State) flags, how to read them from the authenticator-data flags byte, the meaning of each valid combination (device-bound, syncable-but-not-backed-up, synced) and the invalid BE=0/BS=1 state, and provides operational guidance: store BE at registration, re-read BS on every assertion, reject impossible combinations, and use these flags to drive recovery and policy decisions while avoiding common implementation mistakes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
