PKT-PASSKEY-SIGN — transport probe
Probe fixture. Not product code. Answers Q-1 / Q-3 / Q-5 of
packets/PKT-PASSKEY-SIGN/spec.md §(h.2). Nothing here is sent anywhere:
every byte stays in this page. Signs only the challenge you enter.
0 — environment (Q-1, Q-3)
reading…
1 — create a credential (Q-5: device-bound or synced?)
RP ID (must equal this host, or a registrable parent of it)
authenticatorAttachment
platform (Face ID / Touch ID — the phone's own)
cross-platform (hardware security key)
(unset — let the platform choose)
residentKey
required
preferred
discouraged
CREATE — one Face ID / Touch ID gesture
not run
2 — assert over a batch hash (Q-2 size, Q-3 display)
batch payload sha256 (64 hex chars — paste the ceremony's sha)
decoded statement shown to you (this is the RP page rendering it — the
authenticator renders nothing)
ASSERT — one gesture
not run
copy the envelope JSON
3 — verdict lines to paste back into the receipts document
run steps 0–2