Keycloak supports passkeys and WebAuthn out of the box, with no plugin and, as of 26.7, no
custom authentication flow. The thing worth knowing before you turn either on is that
they are not one feature. Keycloak treats passwordless passkeys and WebAuthn-as-a-second-factor
as two different credentials, registered by two different required actions, governed by two
different policies. A user who has one does not have the other, and nothing in the admin
console tells you so.
This post is the concept half: what passkeys are, how they relate to WebAuthn, how Keycloak
models the difference, and the recovery and cross-platform problems that bite in production.
For the configuration itself — every click, every default value, every failure mode — see the
tutorial linked below.