NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages
Passkeys for Laravel

Algorithms & Ed25519

algorithms lists the COSE algorithm IDs offered and accepted, in preference order. The relying party accepts exactly three:

CaseCOSE IDNotes
ES256-7ECDSA P-256 / SHA-256. On by default.
RS256-257RSASSA-PKCS1-v1_5 / SHA-256. On by default.
EdDSA-8Ed25519. Requires ext-sodium; off by default.

Opting into Ed25519

Ed25519 verification is fully implemented; it is only off by default because it needs ext-sodium. Once that extension is installed on every host that verifies these credentials, add it to config/passkeys.php:

use RoundlyConsulting\Crypto\Cose\CoseAlgorithm;

'algorithms' => [
    CoseAlgorithm::ES256->value,   // -7
    CoseAlgorithm::RS256->value,   // -257
    CoseAlgorithm::EdDSA->value,   // -8 (requires ext-sodium)
],

No algorithm confusion

The CoseAlgorithm registry comes from crypto-for-laravel and is deliberately wider — it also carries ES384 and ES512. This relying party accepts only ES256, RS256 and EdDSA (PasskeyConfig::SUPPORTED_ALGORITHMS); configuring any other identifier throws InvalidConfiguration at boot rather than offering an algorithm the ceremony has not been vetted against.

At sign-in, the verification algorithm is read from the stored credential’s own COSE key — never from the assertion — and the configured allow-list is enforced at registration.

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.