Eiji Kitamura / えーじ :verified:

Chrome @ Google - Developer Advocate at the Web Developer Relations — Identity tech lead.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-12-16

Signal API for passkeys is now available on Chrome for Android.

A user deletes their credential on the website, but the passkey remains in their passkey provider. The next time they try to sign in, the passkey provider offers a passkey that no longer works. A sign-in attempt will surely fail and this is such a bad experience.

The Signal API solves this by allowing your website to "signal" the current state of credentials to the passkey provider. You can tell the provider to delete invalid passkeys or update metadata, ensuring a seamless sign-in experience.

Learn more: developer.chrome.com/blog/sign

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-12-14

Capturing the overview of passkeys is difficult, especially if you are chasing updates. I wrote a personal blog post that captures an end of 2025 version of passkey keywords so you know what to learn.

Key terminologies to get a grasp of passkeys
blog.agektmr.com/en/2025/12/pa

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-12-08

4 new ways Chrome autofill will simplify your holidays
blog.google/products/chrome/au
Chrome can now remember your loyalty card and flight details for faster submission, along with an improved autofill experience on Android.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-11-18

RE: infosec.exchange/@agektmr/1152

I'm in SYD to give this talk at Web Directions Developer Summit. See you there.

Eiji Kitamura / えーじ :verified: boosted:
World Wide Web Consortiumw3c@w3c.social
2025-11-12

Hallway conversations are some of our #w3cTPAC attendees favorite parts of the week.

We’ll be sharing more photos throughout the week. Attendees, please feel free to share your own!

three people stand talking to each other
Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-11-07

For those coming to Japan to attend TPAC, welcome! Hope you enjoy your stay here.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-11-07
Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-11-05

@paul @AlesandroOrtiz @developers Thanks for the report! We'll fix it soon.

Eiji Kitamura / えーじ :verified: boosted:

i'm glad that no matter what the current state of the world is We get to witness the japanese gboard team's descent into insanity

Screencap from the "Gboard Dial Version" reveal video, showing their rotary dial layout keyboard.
Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-10-23

DBSC (Device Bound Session Credentials) has started its second origin trial on Chrome .

DBSC is a browser mechanism that allows websites to bind session credentials such as cookies to a device so that it can mitigate chances for cookie thefts. In this origin trial, we have changed some header names, jwt schema, http status and so on. With origin trial, you can allowlist your website domain to enable the feature.

Learn more from: developer.chrome.com/blog/dbsc

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-10-12

@Jespertheend `NotAllowedError` indicates conditions didn't meet developer.chrome.com/docs/iden
Unfortunately, passwordless flows are not supported in general. I'm not aware of any plans to support passwordless flows.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-10-11

@Jespertheend it's already available on all Chrome desktop platforms.
developer.chrome.com/blog/pass
And because Safari on iOS26 supports it, Chrome there also supports it.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-10-10

One correction: The feature is still in beta and available from next stable version—Chrome 142.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-10-10

Chrome for Android can now help users adopt passkeys more seamlessly.

If a user signs in with a saved password, your website can request that Google Password Manager (GPM) create a passkey automatically using a WebAuthn API feature called "Conditional Create". Chrome does not interrupt the user. After creation, Chrome shows a brief confirmation and a Manage button that opens the new passkey in Google Password Manager settings. Users can turn this feature off in Google Password Manager settings.

This feature has been available on Chrome desktop, but it's now available on Android too!

Learn more: developer.chrome.com/blog/auto

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-10-08

Digital Credentials API is now available on Chrome!

Thanks everyone for participating in and sending feedback to the Digital Credentials API origin trial. After some refinement, we've successfully shipped Digital Credentials API on Chrome starting in its version 141.

With Digital Credentials API, users can prove their identity using a digital credential served from one of digital wallets they have, such as Google Wallet. These credentials are carefully designed so only necessary part can be presented, for example, age verification is possible without revealing the birth day.

Continue to the announcement to learn more:
developer.chrome.com/blog/digi

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-09-22

Excited to be speaking at FIDO Alliance's Authenticate US 2025 with my amazing colleague Niharika Arora about "𝐖𝐡𝐚𝐭’𝐬 𝐧𝐞𝐰 𝐨𝐧 Google 𝐩𝐥𝐚𝐭𝐟𝐨𝐫𝐦s 𝐟𝐨𝐫 𝐏𝐚𝐬𝐬𝐤𝐞𝐲𝐬"
authenticatecon.com/event/auth

Happy to catch-up if you are joining and discuss all Identity things!

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-09-22

Excited to be delivering State of identity and authentication on the web at Web Directions Developer Summit in Sydney (and online) November 19 and 20, and I'd love to see you there.
webdirections.org/dev-summit/s

Get $200 off in person with the code "eijidevsummit25" and $100 off a streaming ticket with the code "eijidevsummit25streaming".

Learn more at webdirections.org/dev-summit , and hope to see you there!

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-09-07

@mcrocker @faoluin FIDO/WebAuthn looks a superior superset of SQRL to me. But I see your point.

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-09-07

@mcrocker @faoluin I haven't read the spec in details, but who owns the SQRL client? Where does the private key go after creating an account? What happens when the user switches to a new device?

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2025-09-05

@mcrocker I see what you mean, but strict security and open source solutions aren't always the best combination. Platforms want to keep non-tech savvy people safe by designing things robust and easy to use, but that can keep flexible solutions like open source products away. At least, we are trying to keep them in the ecosystem yet. Let me know what you think are missing now.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst