meta

No Display? No Problem: Cross-Device Passkey Authentication for XR Devices (opens in new tab)

Passkeys provide phishing-resistant authentication, but standard cross-device flows depend on QR codes displayed on the device being authenticated. This creates a problem for XR headsets, smart-home hubs, sensors, and other devices with no accessible screen. The proposed solution uses an authenticated companion app to transport the FIDO hybrid-flow request, preserving proximity, trust, and standard WebAuthn security without requiring a QR code.

The Challenge: Screenless Devices Cannot Display QR Codes

  • Traditional cross-device passkey authentication uses:
    • A QR code displayed by the desktop or other target device.
    • Bluetooth or NFC to verify proximity and establish communication.
  • Devices without usable displays cannot show a QR code for a phone to scan.
  • Proximity discovery alone is insufficient because users still need a clear, secure way to approve the correct authentication request.

Companion Apps as Secure Message Transport

  • The target device generates the same hybrid-flow request normally encoded in a QR code.
  • Instead of displaying it, the device sends the request to an authenticated companion app associated with the same user account.
  • In-app notifications provide a user-consent surface and direct the user into the passkey flow.
  • Opening the app itself can initiate the flow because the user must deliberately open it, and mobile operating systems provide an additional verification step.

Meta Quest and Meta Horizon Implementation

  • The implementation is broadly available on Meta Quest devices running Meta Horizon OS.
  • The Quest browser creates a FIDO URL containing:
    • A fresh ECDH public key.
    • A session-specific secret.
    • Routing information for the hybrid handshake.
  • The URL is packaged as structured data in a GraphQL-based push notification.
  • The Meta Horizon app validates that the request belongs to the correct signed-in user before processing it.

Notification and Deep-Link Flow

  • iOS or Android displays a notification that a passkey login is pending.
  • Tapping the notification opens the Meta Horizon app, which launches the FIDO URL through the operating system.
  • The OS then invokes its passkey interface.
  • If notifications are disabled, opening the app queries the backend for pending requests.
  • Requests expire after five minutes, limiting the window for misuse.
  • The mobile device then performs the normal hybrid transport process:
    • Broadcasting a BLE advertisement.
    • Establishing an encrypted tunnel.
    • Generating the passkey assertion.

WebAuthn Challenge and Response

  • The inaccessible device creates the normal WebAuthn challenge and waits for a response.
  • The mobile authenticator initiates the secure BLE or NFC connection.
  • The challenge travels through the encrypted channel.
  • After successful user verification, the phone creates an AuthenticatorAssertionResponse or AuthenticatorAttestationResponse.
  • The inaccessible device forwards that response to the relying-party server just as a display-equipped device would.

Broader Impact

  • The approach removes the QR-code requirement while retaining FIDO hybrid transport and proximity protections.
  • It could extend passwordless authentication to:
    • XR headsets and wearables.
    • Screenless IoT devices.
    • Smart-home hubs.
    • Industrial sensors and hardware.
  • The work builds on FIDO Alliance standards and mobile operating-system support, helping broaden interoperability across device ecosystems.

The companion-app model offers a practical way to bring secure cross-device passkeys to devices that cannot display QR codes. It is especially suitable where the device already has an authenticated mobile app and can rely on standard WebAuthn, BLE/NFC proximity, and platform user verification.