All enums live in RoundlyConsulting\Passkeys\Enums and use the Helpers trait from enums-for-laravel (values(), options(), …). Their raw values are what serialise into ceremony JSON and what the config stores:
| Enum | Cases (value) | Used by |
|---|---|---|
UserVerification | Required, Preferred, Discouraged | user_verification and both overrides DTOs |
ResidentKey | Required, Preferred, Discouraged | resident_key and RegistrationOptionsOverrides |
AuthenticatorAttachment | Platform (platform), CrossPlatform (cross-platform) | RegistrationOptionsOverrides |
AttestationConveyance | None, Indirect, Direct | attestation and RegistrationOptionsOverrides |
AttestationTrust | Ignore (ignore), SelfAttested (self), Basic (basic) | attestation_trust |
AttestationType | None, Self, Basic, AttCa (attca), AnonCa (anonca) | The attestation_type column |
SignCountPolicy | Reject (reject), Flag (flag) | sign_count_policy |
CeremonyType | Registration, Authentication | Stored with each challenge |
- Values are the lowercase case names unless shown in brackets.
- ResidentKey::requireResidentKey() returns the legacy boolean the spec still emits alongside residentKey — true only for Required.
- AttestationType::AttCa is reserved for the tpm format, which the package doesn’t verify today. Basic and AttCA are indistinguishable to a relying party, so packed batch certificates report basic.
- CeremonyType lets the verifier reject a challenge presented to the wrong ceremony, independent of the clientData.type check.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.