[PM-42948] WebAuthn two-step login cannot find previously registered passkey on iOS
- Dominant language
- Swift
- Stars
- 684
- Forks
- 154
- Avg merge
- 7d 2h
- Merged PRs (30d)
- 32
Description
### Steps To Reproduce
Prerequisites:
- WebAuthn/FIDO2 is configured as a two-step login method for my Bitwarden account.
- I previously registered an iPhone as a WebAuthn two-step login authenticator.
- The same Bitwarden account can still complete WebAuthn two-step login successfully on my Mac.
- "Log in with passkey" also continues to work on the same iPhone.
Steps to reproduce:
1. Open Bitwarden Password Manager on the iPhone.
2. Log in using the email address and master password.
3. At the two-step login screen, choose WebAuthn/FIDO2.
4. Continue to the iOS passkey authentication prompt.
5. iOS reports that no matching passkey is saved for the Bitwarden domain.
I can also reproduce the problem outside the Bitwarden app:
6. Open the Bitwarden Web Vault in Safari on the same iPhone.
7. Log in using email + master password and choose WebAuthn/FIDO2 for two-step login.
8. The existing WebAuthn credential is not found there either.
9. I also tried logging in on an iPad and selected the option to use a passkey from another device.
10. I scanned the QR code with the iPhone.
11. The iPhone again reported that no matching passkey was saved for the Bitwarden domain.
### Expected Result
The WebAuthn/FIDO2 credential that was previously registered using this iPhone for Bitwarden two-step login should be discovered and offered by iOS, allowing the WebAuthn two-step authentication to complete successfully.
The credential should also be available when the same WebAuthn authentication request is initiated from Safari or through cross-device authentication using a QR code.
### Actual Result
The WebAuthn/FIDO2 credential previously registered for Bitwarden two-step login is no longer discovered on the iPhone.
When authentication is attempted in the Bitwarden iOS app, iOS reports that no matching passkey is saved for the Bitwarden domain.
The same behavior occurs when:
- attempting WebAuthn two-step login through the Bitwarden Web Vault in Safari on the same iPhone; and
- initiating WebAuthn authentication on an iPad and scanning the cross-device QR code with the iPhone.
However, the same Bitwarden account can still complete WebAuthn two-step login on my Mac.
Additionally, Bitwarden's "Log in with passkey" feature continues to work normally on the same iPhone.
Therefore, passkey functionality on the iPhone is not completely broken; the problem appears specifically related to the credential previously registered for WebAuthn/FIDO2 two-step login.
### Screenshots or Videos
_No response_
### Additional Context
Environment:
- Bitwarden Password Manager for iOS: 2026.8.0
- iOS: 27.0 beta 8 (24A5430a)
- Apple Passwords / iCloud Keychain: enabled
- Bitwarden WebAuthn/FIDO2 two-step login: enabled
- Bitwarden "Log in with passkey": works normally on the same iPhone
- WebAuthn two-step login on macOS: works normally
Important context:
The WebAuthn credential used for two-step login was originally registered using my iPhone. It previously worked on the iPhone, but after some time the iPhone stopped discovering it.
This is different from Bitwarden's "Log in with passkey" feature. Passkey login still works normally on the same iPhone.
The issue can also be reproduced in Safari and through cross-device WebAuthn authentication (iPad displaying a QR code -> iPhone scanning the QR code), where iOS reports that no matching passkey is available.
Because I am currently running iOS 27.0 beta 8, I understand that this could potentially be an iOS/WebAuthn regression rather than a Bitwarden-specific issue. I am reporting it here because the affected credential was created specifically for Bitwarden WebAuthn two-step login, while Bitwarden passkey login continues to work.
### Build Version
2026.8.0
### What server are you connecting to?
US
### Self-host Server Version
_No response_
### Environment Details
_No response_
### Issue Tracking Info
- [ ] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
Contributor guide
Research direction
No source files or tests are identified. Start by reproducing the flow on iOS 27.0 beta 8 in the iOS app, Safari, and cross-device QR authentication, then compare it with Mac WebAuthn and iPhone passkey login; done means the previously registered two-step WebAuthn credential is discovered on iPhone.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ios, swift
- Domain
- authentication, mobile
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100