Tim Cappalli
- Editor of the W3C Web Authentication and Digital Credentials API specifications
- Led work on the first generation of passkeys while at Microsoft
- Maintainer of passkeys.dev and digitalcredentials.dev
Bio
Tim Cappalli is a standards architect at Okta and an editor of both the W3C Web Authentication specification and the newer Digital Credentials API. He led work on the first generation of passkeys at Microsoft and maintains passkeys.dev and digitalcredentials.dev, the reference sites most implementers actually read.
Profile built from public W3C, FIDO Alliance, and employer records.
Where their work shows up
WebAuthn gave the browser a way to ask for a phishing-resistant credential. The Digital Credentials API does the same job for a government-issued credential in a wallet, so a website can request a driving licence or an age proof through a browser-mediated flow rather than a bespoke app handoff. Together they are the two browser primitives wallet-based identity depends on. See implementing passkeys in the enterprise and the mobile driving licence standard.
Related on Start with Identity
- Blog94 percent of enterprises say they can revoke access in 24 hours. 35 percent found out they couldn't.
FIDO Alliance and HID surveyed 500 IT and security decision-makers for The State of Physical and Digital Identity in the Enterprise. The headline gap: near-univ
- BlogAmazon says 175 million customers now sign in with passkeys
Amazon reports more than 175 million customers have enabled passkeys, signing in six times faster, with passkeys now the default on mobile for anyone who has se
- BlogBlack Hat USA 2026 recap: passkeys get broken (twice), and AI agents get an identity perimeter
Our identity takeaways from Black Hat USA 2026: two independent passkey implementation attacks, a wave of AI agent identity and governance launches, an open sou
- GlossaryFIDO2
FIDO2 is a set of specifications from the FIDO Alliance plus W3C. It combines WebAuthn (the browser API) with CTAP (the client-to-authenticator protocol) to ena
- GlossaryPasskey
A passkey is a WebAuthn public-key credential that replaces a password. Possession of the authenticator plus a user verification step proves identity, with no s
- GlossaryPasswordless
Authentication without a password as a primary factor. Implementations include magic links, OTP codes, and passkeys. Passkeys are the only passwordless method t