I use passkeys wherever they’re available, and I’m not worried that WebAuthn has forgotten which site requested authentication. The protocol binds the request to the origin. My concern is the moment before approval: a familiar-looking biometric prompt can arrive while I’m unsure which tab, browser context, device, or account triggered it.
That makes low-friction approval a potential origin-confusion habit. Before I approve, the OS or browser should plainly show the exact origin, the account being used, and the requested action—not just a small domain label. “Sign in to example.com as alex@example.com” is much more useful than a generic biometric gesture. Account labels can be available to the authenticator, but the action is application-specific, so today’s presentation may not be consistent.
Should operating systems and browsers standardize a prominent pre-approval summary like this? Disagree, share a real-world example, or propose a better interface.