October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk6 min

How to Use Selenium 4 WebAuthn Virtual Authenticator Commands

A practical Selenium Python guide to configuring virtual authenticators, testing WebAuthn credential flows, and avoiding common lifecycle mistakes.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Selenium 4’s authentication commands let a test create a virtual authenticator and manage its WebAuthn credentials. In Python, the core workflow is to configure and attach the authenticator, let the application page perform registration or authentication, assert the result, then clean up. These are WebAuthn testing controls—not generic login bypass commands—and they do not replace the application’s server-side authentication logic.

What Selenium’s authentication commands do

Selenium’s virtual-authenticator API gives WebDriver tests a software authenticator with selected properties. The page under test still calls the browser’s WebAuthn API to register or use a credential; Selenium supplies the simulated authenticator behavior. WebAuthn credentials are public-key credentials scoped to a relying party, as described by the W3C WebAuthn Level 3 Recommendation.

As an Amazon Associate I earn from qualifying purchases.

This approach is useful for exercising application registration and assertion flows in a controlled test. It does not prove that a physical security key or production authenticator works. The examples below use the Selenium Python API; do not assume that argument names or command availability are identical across language bindings or every Selenium 4 release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which commands and options matter

Authenticator lifecycle

  • driver.add_virtual_authenticator(options) attaches a configured virtual authenticator to the driver.
  • authenticator.add_credential(credential) adds a credential to it.
  • authenticator.get_credentials() returns its stored credentials.
  • authenticator.remove_credential(credential_id) removes one credential.
  • authenticator.remove_all_credentials() clears its credentials.
  • driver.remove_virtual_authenticator() removes the authenticator. Once removed, it is invalid; do not call methods on it afterward.

Options should match the behavior you need to test

The Python options include protocol (ctap2 or ctap1/u2f), transport, resident-key support, user-verification support, user-consent behavior, and user-verified state. Credential properties can include the credential ID, relying-party ID, resident status, user handle, private key, and signature count. Choose these to match the relying party’s scenario rather than treating one configuration as universally best. For the documented Python API, see Selenium’s virtual authenticator reference.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Python example: register, inspect, and clean up

This example shows the test lifecycle. It assumes the test application has a registration control and reports success in an element with ID registration-status; replace the URL, locator, and assertion with those used by your application. It uses Selenium’s Python virtual-authenticator options and credential APIs. Install Selenium and a compatible browser driver for your environment; verify the API and browser support for the versions you run.

from selenium import webdriver
from selenium.webdriver.common.by import By
from selenium.webdriver.common.virtual_authenticator import (
    VirtualAuthenticatorOptions,
    Credential,
)

options = webdriver.ChromeOptions()
driver = webdriver.Chrome(options=options)
authenticator = None

try:
    authenticator_options = VirtualAuthenticatorOptions()
    authenticator_options.is_user_verified = True
    authenticator = driver.add_virtual_authenticator(authenticator_options)

    driver.get("https://example.test/account/security")
    driver.find_element(By.ID, "register-passkey").click()

    # Replace this condition with the application's actual success signal.
    status = driver.find_element(By.ID, "registration-status")
    assert "registered" in status.text.lower()

    credentials = authenticator.get_credentials()
    assert credentials, "The registration flow did not create a credential"

    # Optional: remove one credential when the test scenario requires it.
    # authenticator.remove_credential(credentials[0].id)

finally:
    if authenticator is not None:
        driver.remove_virtual_authenticator()
    driver.quit()

The click and success assertion are application-specific; the virtual authenticator does not register a credential by itself. The registration page must invoke WebAuthn, and the test should assert the outcome meaningful to the application as well as any authenticator state it needs to inspect.

Preload a credential for an authentication test

For a sign-in scenario that expects an existing credential, construct a Credential using the fields required by the Selenium Python version in use, then add it before navigating to the sign-in flow. Credential details such as a private key, credential ID, relying-party ID, user handle, resident status, and signature count must be internally appropriate for the test; do not copy placeholder values into a real test. Consult the version-matched Python API reference for constructor arguments. The relying-party page still initiates WebAuthn authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Choose a configuration by test scenario

Scenario dimension What to configure Why it matters
Protocol CTAP2 or CTAP1/U2F Simulates the protocol behavior the relying party needs to support.
Transport For example, USB or internal, where exposed by the binding Lets a test exercise assumptions tied to how an authenticator is presented.
Resident/discoverable credentials Set resident-key support and credential resident status as required Tests flows that depend on discoverable credentials rather than only a server-provided credential identifier.
User verification Configure support and user-verified state to reflect the scenario Distinguishes a test that can satisfy a verification requirement from one that cannot.
User consent Set the relevant consent behavior in options Allows the test to model the authenticator behavior expected by the flow.

These are simulation choices, not claims about the behavior of every real key. Match them to the relying party’s tested requirements and verify option names against the Selenium binding/version in use.

Clean up credential and authenticator state

Use remove_credential(credential_id) when a test needs to delete one credential, or remove_all_credentials() when it needs to clear the authenticator while keeping it available. After assertions, call driver.remove_virtual_authenticator() as part of teardown. The authenticator becomes invalid at that point, so do not query or modify it afterward. A finally block, as in the example, helps ensure teardown runs when an assertion or interaction fails.

Troubleshooting

The WebAuthn flow does not create a credential

Check that the test clicked the application’s registration path and that the page called WebAuthn. Adding an authenticator only configures the test device; it does not cause the page to register a credential. Assert the application’s own success signal and inspect stored credentials if appropriate.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

A command or option is missing

Confirm that the code uses the API documented for the installed Selenium Python version and that the selected driver/browser supports the virtual-authenticator operation. The cited references do not establish a universal compatibility matrix across browsers, bindings, and releases; avoid assuming support based solely on the major version number.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Calls fail after teardown

Do not use an authenticator object after calling remove_virtual_authenticator(). Finish credential inspection and cleanup operations first, then remove it.

The test passes but does not validate a physical authenticator

A virtual authenticator is software-based test infrastructure. If the requirement concerns a real hardware key, this workflow alone does not establish hardware compatibility; plan a separate hardware test.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Chrome DevTools adds as a manual reference

Chrome DevTools documents a comparable manual workflow: enable its WebAuthn virtual-authenticator environment, add an authenticator, register through a WebAuthn page, inspect credential IDs, user handles, and sign counts, then remove the authenticator. That is useful for understanding the lifecycle, but Selenium code should follow Selenium’s own API rather than DevTools command names. See the Chrome DevTools WebAuthn documentation.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server, not a WebAuthn authenticator and not a replacement for Selenium’s credential testing. If your adjacent task is capturing a rendered page, a single request can return an image or PDF:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

See the ScreenshotNeo API documentation. It removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots, and 1,000 screenshots a month are free without a card; paid plans start at $5 for 3,000. Learn more at ScreenshotNeo. Sign up for free.

Frequently Asked Questions

Can Selenium’s virtual authenticator bypass a website’s login?

No. It supplies simulated WebAuthn authenticator behavior for a test; the application still runs its registration or authentication flow and server-side checks.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Does this prove a physical security key works?

No. A virtual authenticator is software-based and does not establish compatibility with real hardware.

Can I use the same API calls in every Selenium language binding?

Do not assume so. The detailed example here is for Selenium Python; check the documentation for the binding and version you use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.