Featured Developer Sponsor • Zero-Token Protection
W3C Identity Standard
Cookie-Less Federation
W3C FedCM & Privacy-Preserving Identity Studio
Simulate browser-mediated identity federation via the W3C FedCM API. Configure IdP manifests, test the Login Status API, inspect Auto Re-authentication, and model IdentityCredential token exchanges without third-party cookies.
1. Identity Provider (IdP) Configuration
2. Relying Party (RP) Parameters
Browser-Mediated Native Sheet
Rendered natively by the browser outside the DOM boundary to prevent clickjacking:
ID
Sign in to SaaS App
To continue, IdP will share your name, email, and avatar with this website.
FedCM Protocol Security Trace
Identity Assertion & Privacy Telemetry
3rd-Party Cookies
0 Required
Sec-Fetch-Dest: webidentity
Passive Tracking
Eliminated
IdP blind until consent
Auto Re-auth Latency
42 ms
Zero UI prompt round-trip
Credential Form
IdentityCredential
Signed JWT token
Production Implementation Blueprint
Frequently Asked Technical Questions
What is W3C Federated Credential Management (FedCM) and why was it created?+
Federated Credential Management (FedCM) is a browser standard (W3C Web Incubator / Federated Identity Working Group) designed to provide a privacy-preserving foundation for federated identity ("Sign in with Google/Apple/IdP"). Previously, federated identity depended on third-party cookies in cross-origin iframes or top-level URL redirect parameters (bounce tracking). As modern browsers enforce third-party cookie phaseouts and bounce-tracking mitigations, legacy federation broke. FedCM introduces browser-mediated identity prompts that render natively outside the page DOM.
How does the Login Status API prevent passive IdP tracking?+
In legacy federation, an IdP could track a user's browsing habits simply by receiving silent iframe requests whenever the user visited any website embedding its SDK. FedCM resolves this via the Login Status API (navigator.login.setStatus({ status: "logged-in" })). The browser stores a privacy bit for each IdP. If the status is "logged-out", the browser rejects navigator.credentials.get() immediately without making any network request to the IdP, ensuring zero tracking of non-logged-in users.
What are the required HTTP endpoints in an IdP FedCM manifest?+
An IdP must serve a well-known config at /.well-known/web-identity pointing to a JSON manifest. The manifest defines: accounts_endpoint (returning active user sessions), client_metadata_endpoint (privacy policy and terms URLs), id_assertion_endpoint (issuing the signed identity token), and optional endpoints like revocation_endpoint and disconnect_endpoint. All requests carry the Sec-Fetch-Dest: webidentity HTTP header to prevent CSRF.
How does FedCM Auto Re-authentication work?+
Auto Re-authentication allows returning users who previously signed in to an application using FedCM to be re-authenticated seamlessly without an interactive prompt. If the Relying Party specifies mediation: "optional" or "conditional", and the browser detects exactly one previously approved account in the IdP accounts response, the browser immediately requests and resolves an identity assertion, slashing authentication latency to tens of milliseconds.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement