Start with Identity
Protocols & Standards

Tim Cappalli

Standards Architect · Okta · 15+ years in identity
Focus areas
WebAuthnPasskeysDigital Credentials APIPhishing Resistance
Notable work
  • Editor of the W3C Web Authentication and Digital Credentials API specifications
  • Led work on the first generation of passkeys while at Microsoft
  • Maintainer of passkeys.dev and digitalcredentials.dev

Bio

Tim Cappalli is a standards architect at Okta and an editor of both the W3C Web Authentication specification and the newer Digital Credentials API. He led work on the first generation of passkeys at Microsoft and maintains passkeys.dev and digitalcredentials.dev, the reference sites most implementers actually read.

Profile built from public W3C, FIDO Alliance, and employer records.

Where their work shows up

WebAuthn gave the browser a way to ask for a phishing-resistant credential. The Digital Credentials API does the same job for a government-issued credential in a wallet, so a website can request a driving licence or an age proof through a browser-mediated flow rather than a bespoke app handoff. Together they are the two browser primitives wallet-based identity depends on. See implementing passkeys in the enterprise and the mobile driving licence standard.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].