Auth
Authentication screens — sign in / sign up with split brand panels, testimonial sidebars and patterned backdrops, plus two-factor, password-recovery and email-verification cards.
Preview
@props([
// WebAuthn endpoints: options (returns request options JSON) and verify
// (POST, receives the assertion). The defaults are the laravel/passkeys
// routes; any backend works.
'optionsUrl' => '/passkeys/login/options',
'verifyUrl' => '/passkeys/login',
// Where to go after a successful sign-in (a `redirect` in the verify
// response wins).
'redirect' => '/',
// Backend contract, passed to the passkey item: 'laravel-passkeys' or null,
// and the single settings a preset makes (see the passkey item).
'preset' => null,
'optionsMethod' => null,
'optionsKey' => null,
'credentialKey' => null,
// Extra verify body fields, for example ['remember' => true].
'body' => [],
// The other way in: a passkey is never the only path.
'fallbackHref' => '#',
'fallbackLabel' => 'Sign in with email instead',
'signupHref' => null,
'heading' => 'Sign in',
'headingTag' => 'h2',
])
{{--
Auth Passkey — sign in with a passkey. One primary action runs the WebAuthn
ceremony through <x-ui.passkey>; its status line explains a dismissed
prompt, a server error or a browser without passkey support, and a link
always offers the other sign-in method.
--}}
@php
$headingTag = in_array($headingTag, ['h1', 'h2', 'h3'], true) ? $headingTag : 'h2';
@endphp
<x-ui.section
data-slot="block-auth-passkey"
aria-labelledby="auth-passkey-heading"
space="md" class="flex min-h-[36rem] items-center justify-center px-4" {{ $attributes }}
>
<x-ui.card class="w-full max-w-md">
<x-ui.card.header class="items-center text-center">
<div class="mb-4 grid size-10 shrink-0 place-items-center rounded-md bg-muted text-foreground" aria-hidden="true">
<svg class="size-5" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="8" cy="15" r="4" /><path d="m10.85 12.15 7.65-7.65M18 5l2 2M15 8l2 2" /></svg>
</div>
<{{ $headingTag }} id="auth-passkey-heading" class="text-xl font-semibold tracking-tight text-card-foreground">{{ __($heading) }}</{{ $headingTag }}>
<x-ui.card.description>
{{ __('Use the passkey saved on this device, a phone nearby or a security key. No password needed.') }}
</x-ui.card.description>
</x-ui.card.header>
<x-ui.card.content class="flex flex-col gap-6">
<x-ui.passkey
:options-url="$optionsUrl" :verify-url="$verifyUrl" :redirect="$redirect"
:preset="$preset" :options-method="$optionsMethod" :options-key="$optionsKey"
:credential-key="$credentialKey" :body="$body"
/>
<div class="relative flex items-center gap-4">
<span class="h-px flex-1 bg-border" aria-hidden="true"></span>
<span class="text-xs text-muted-foreground">{{ __('or') }}</span>
<span class="h-px flex-1 bg-border" aria-hidden="true"></span>
</div>
<x-ui.button :href="$fallbackHref" variant="outline" class="w-full">{{ __($fallbackLabel) }}</x-ui.button>
</x-ui.card.content>
@if (filled($signupHref))
<x-ui.card.footer class="justify-center">
<p class="text-center text-sm text-muted-foreground">
{{ __("Don't have an account?") }}
<a href="{{ $signupHref }}" class="ms-2 font-medium text-link hover:underline">{{ __('Sign up') }}</a>
</p>
</x-ui.card.footer>
@endif
</x-ui.card>
</x-ui.section>
Installation
php artisan ui:add blocks/auth-passkey
Registry contract
Install confidence
php artisan ui:add blocks/auth-passkey
writes only the generated targets below. The CLI validates each file hash before writing and
prompts before replacing local changes unless --force is used.
- Version
- 1.1.1
- License
- open
- Stability
- stable
- Contract
- v4
- Foundation
- ≥ 1.0.0
| Type | Generated target |
|---|---|
| blade | resources/views/blocks/auth-passkey.blade.php |
Registry dependencies
Package dependencies
composer: jml/brok:^0.2
Use with AI
A brief for your coding agent: what the block is, the install command, how to render it, its props and the rules. Copy it, or open a prompt about this block in an assistant.
# Brok UI block: Auth Passkey (`auth-passkey`)
A centered sign-in card whose one primary action runs the passkey (WebAuthn) ceremony, with a status line for every outcome and a link to the other sign-in method.
Brok UI is a Laravel Blade registry. `ui:add` copies this block into the app as plain Blade the app owns; it composes installed `<brok:*>` primitives and semantic design tokens.
## Install
```bash
php artisan ui:add blocks/auth-passkey
```
## Render it
```blade
<x-blocks.auth-passkey />
```
## Props
- `options-url` (string, default `/passkeys/login/options`) — Endpoint that returns WebAuthn request options JSON (the laravel/passkeys login options route by default).
- `verify-url` (string, default `/passkeys/login`) — POST endpoint that verifies the assertion (the laravel/passkeys login route by default).
- `redirect` (string|null, default `/`) — Where to go after sign-in; a redirect in the verify response wins.
- `preset` (string|null, default `null`) — Passed to <x-ui.passkey>: 'laravel-passkeys' speaks the laravel/passkeys contract (GET options wrapped in options, the credential under credential).
- `options-method` (GET|POST|null, default `null`) — Passed to <x-ui.passkey>. HTTP method of the options request. Null uses the preset, else POST. GET sends no body.
- `options-key` (string|null, default `null`) — Passed to <x-ui.passkey>. Response key that wraps the options, for example options. Null uses the preset, else publicKey or the top-level object.
- `credential-key` (string|null, default `null`) — Passed to <x-ui.passkey>. Verify body field that holds the credential, for example credential. Null uses the preset, else the credential is the body.
- `body` (array, default `[]`) — Extra verify body fields passed to <x-ui.passkey>, for example ['remember' => true] for laravel/passkeys.
- `fallback-href` (string, default `#`) — Link to the other sign-in method. A passkey is never the only path.
- `fallback-label` (string, default `Sign in with email instead`) — Label of the fallback link.
- `signup-href` (string|null, default `null`) — Optional sign-up link in the card footer.
- `heading` (string, default `Sign in`) — Card heading.
- `heading-tag` (string, default `h2`) — Heading level: h1, h2 or h3.
## Use when
- A sign-in screen offers passkeys and the server exposes WebAuthn request options and verify endpoints.
- The passkey is the primary way in and a second method stays one click away.
## Avoid when
- Email magic links or one-time codes are the only passwordless method; use auth-passwordless.
- The passkey is a secondary option inside a password form; place <x-ui.passkey> in auth-sign-in instead.
## Rules
- Render the installed block with `<x-blocks.auth-passkey />` and pass data through its props; edit the copied file only for structural changes.
- Keep the semantic design tokens (`bg-background`, `text-muted-foreground`); never swap in raw colour utilities.
- Keep the `data-slot` attributes and the logical (start/end) spacing so the markup still mirrors under `dir="rtl"`.
## Links
- Docs: https://brokui.dev/blocks/auth-passkey
- Registry JSON (files, props, contract): https://brokui.dev/r/open/blocks/auth-passkey.json
Working in Claude Code, Cursor or Codex? Give the agent the whole registry through the MCP server or the Brok UI skill.
Guidance
Use when
- A sign-in screen offers passkeys and the server exposes WebAuthn request options and verify endpoints.
- The passkey is the primary way in and a second method stays one click away.
Avoid when
- Email magic links or one-time codes are the only passwordless method; use auth-passwordless.
- The passkey is a secondary option inside a password form; place <x-ui.passkey> in auth-sign-in instead.
Anti-patterns
- Do not replace semantic props with conflicting utility classes.
- Do not remove labels, focus styles, or state attributes.
- Anatomy
- Theming hooks
Usage
Render the block as a component, passing data where useful:
<x-blocks.auth-passkey />
Built from primitives
This block composes installed <brok:*> primitives and semantic design
tokens only — it does not reimplement any primitive. Re-theme it (light, dark, admin, customer) by
editing CSS variables; flip the preview to RTL to confirm it mirrors.
Source
The exact, editable file ui:add writes
into your app. The preview above renders this same source — there are no preview-only blocks.
@props([
// WebAuthn endpoints: options (returns request options JSON) and verify
// (POST, receives the assertion). The defaults are the laravel/passkeys
// routes; any backend works.
'optionsUrl' => '/passkeys/login/options',
'verifyUrl' => '/passkeys/login',
// Where to go after a successful sign-in (a `redirect` in the verify
// response wins).
'redirect' => '/',
// Backend contract, passed to the passkey item: 'laravel-passkeys' or null,
// and the single settings a preset makes (see the passkey item).
'preset' => null,
'optionsMethod' => null,
'optionsKey' => null,
'credentialKey' => null,
// Extra verify body fields, for example ['remember' => true].
'body' => [],
// The other way in: a passkey is never the only path.
'fallbackHref' => '#',
'fallbackLabel' => 'Sign in with email instead',
'signupHref' => null,
'heading' => 'Sign in',
'headingTag' => 'h2',
])
{{--
Auth Passkey — sign in with a passkey. One primary action runs the WebAuthn
ceremony through <x-ui.passkey>; its status line explains a dismissed
prompt, a server error or a browser without passkey support, and a link
always offers the other sign-in method.
--}}
@php
$headingTag = in_array($headingTag, ['h1', 'h2', 'h3'], true) ? $headingTag : 'h2';
@endphp
<x-ui.section
data-slot="block-auth-passkey"
aria-labelledby="auth-passkey-heading"
space="md" class="flex min-h-[36rem] items-center justify-center px-4" {{ $attributes }}
>
<x-ui.card class="w-full max-w-md">
<x-ui.card.header class="items-center text-center">
<div class="mb-4 grid size-10 shrink-0 place-items-center rounded-md bg-muted text-foreground" aria-hidden="true">
<svg class="size-5" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="8" cy="15" r="4" /><path d="m10.85 12.15 7.65-7.65M18 5l2 2M15 8l2 2" /></svg>
</div>
<{{ $headingTag }} id="auth-passkey-heading" class="text-xl font-semibold tracking-tight text-card-foreground">{{ __($heading) }}</{{ $headingTag }}>
<x-ui.card.description>
{{ __('Use the passkey saved on this device, a phone nearby or a security key. No password needed.') }}
</x-ui.card.description>
</x-ui.card.header>
<x-ui.card.content class="flex flex-col gap-6">
<x-ui.passkey
:options-url="$optionsUrl" :verify-url="$verifyUrl" :redirect="$redirect"
:preset="$preset" :options-method="$optionsMethod" :options-key="$optionsKey"
:credential-key="$credentialKey" :body="$body"
/>
<div class="relative flex items-center gap-4">
<span class="h-px flex-1 bg-border" aria-hidden="true"></span>
<span class="text-xs text-muted-foreground">{{ __('or') }}</span>
<span class="h-px flex-1 bg-border" aria-hidden="true"></span>
</div>
<x-ui.button :href="$fallbackHref" variant="outline" class="w-full">{{ __($fallbackLabel) }}</x-ui.button>
</x-ui.card.content>
@if (filled($signupHref))
<x-ui.card.footer class="justify-center">
<p class="text-center text-sm text-muted-foreground">
{{ __("Don't have an account?") }}
<a href="{{ $signupHref }}" class="ms-2 font-medium text-link hover:underline">{{ __('Sign up') }}</a>
</p>
</x-ui.card.footer>
@endif
</x-ui.card>
</x-ui.section>
Ownership & lifecycle
Owner, release state, review evidence and adoption for this item.
- Owner
- Platform UI (@JoshJML)
- Current version
-
1.1.1 - Status
- Stable
- License
-
open - Deprecation
- Not deprecated
- Contract
-
v4 - Foundation
-
≥ 1.0.0