[Self-Hosted] Can't Create Passkeys

(#726) Bug Fixed security self-hosting

Summary

When I try to create a passkey, it errors out and nothing happens. The issue occurs with both security keys and digital passkeys stored on a password manager.

Steps to reproduce

  1. Go to Settings > Account > Security
  2. Click on "Add Passkey" next to "Registered Passkeys"
  3. Attempt to create any passkey

Environment

Version: Stable Web 2026.702.163118 OS: Windows NT 10.0 (x64) Browser: Chrome 150.0.0.0 Device: x86_64 PC Locale: en-US

Logs or screenshots

When I tried to create a passkey via YubiKey. Didn't get the popup from Windows Security to create the passkey: image When I tried to create a passkey and add it to my password manager: image
  • 620501945-655c74b3-7db3-4c0b-b8ab-0ceceb470c89.png

    620501945-655c74b3-7db3-4c0b-b8ab-0ceceb470c89.png

    775×460 | 26 kB

  • 620501984-1b80aaeb-03ae-4430-9f46-79b655682315.png

    620501984-1b80aaeb-03ae-4430-9f46-79b655682315.png

    498×131 | 16 kB

3 comments

Sign in with Fluxer to comment and vote.
Comment by @Float-as
RexSystem 1 vote originally by @Float-as on GitHub
Might be related with desktop clients only. I can create passkeys on android using bitwarden and login with them using canary build. But cannot login in desktop on browser (Brave).
Comment by probablyjassin
probablyjassin 1 vote originally by @probablyjassin on GitHub
This isn't exactly a bug, it's just that this needs extra configuration which is not yet fully documented. You need to set: FLUXER_PASSKEY_RP_ID=chat.example.com FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=chat.example.com I checked my .env / x-fluxer-env and I also have FLUXER_PASSKEY_RP_NAME=My_Fluxer set but I don't know whether that was necessary
Comment by @thedepartedwhiplash
RexSystem 1 vote edited originally by @thedepartedwhiplash on GitHub OP
Tried out above and it worked! Specifically, I had to set the following variables in my .env file:
FLUXER_PASSKEY_RP_ID=fluxer.domain.com
FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=https://fluxer.domain.com
as well as in my docker-compose.yml file:
  FLUXER_PASSKEY_RP_ID: ${FLUXER_PASSKEY_RP_ID}
  FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS: ${FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS}
The https:// prefix for ALLOWED_ORIGINS is necessary. Thanks for the help, @probablyjassin!