1 Choose what to ask for
These become the PublicKeyCredentialCreationOptions that the server sends after you
press register. Change them and watch how the response changes.
Start from a typical setup
Most consumer sites ask for almost exactly this: no attestation, a resident (“discoverable”) credential preferred so the passkey can usually be offered without a username, user verification left to the device, no restriction on which authenticator, and the two algorithms that everything supports. It is the shape of the passkey flows on large consumer sites such as GitHub — representative of the pattern rather than a byte-for-byte copy of any one site.
Whether the authenticator keeps the credential on itself, so it can be found without the site naming it.
Whether the authenticator must check it is really you, rather than only that someone is present.
Restricts the choice to a built-in authenticator or to a removable one.
2 What the server is holding about you
This is the whole of the server’s memory about you: one encrypted cookie, and nothing on the server side at all. No other browser can reach it, because there is nothing to look up and the cookie cannot be read or forged without the server’s key.