logo

BE and BS Flags Explained: Telling a Synced Passkey from a Device-Bound One

ID: e720f774-edc4-54b8-b156-8b91ec81d2b5

STIX ID: report--e720f774-edc4-54b8-b156-8b91ec81d2b5

Feed Name: Security Boulevard

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: MojoAuth Blog - Passwordless Authentication & Identity Solutions

...
...

This article explains the WebAuthn BE (Backup Eligibility) and BS (Backup State) flags, how to read them from the authenticator-data flags byte, the meaning of each valid combination (device-bound, syncable-but-not-backed-up, synced) and the invalid BE=0/BS=1 state, and provides operational guidance: store BE at registration, re-read BS on every assertion, reject impossible combinations, and use these flags to drive recovery and policy decisions while avoiding common implementation mistakes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.