Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSelenium 4’s authentication commands let a test create a virtual authenticator and manage its WebAuthn credentials. In Python, the core workflow is to configure and attach the authenticator, let the application page perform registration or authentication, assert the result, then clean up. These are WebAuthn testing controls—not generic login bypass commands—and they do not replace the application’s server-side authentication logic.
What Selenium’s authentication commands do
Selenium’s virtual-authenticator API gives WebDriver tests a software authenticator with selected properties. The page under test still calls the browser’s WebAuthn API to register or use a credential; Selenium supplies the simulated authenticator behavior. WebAuthn credentials are public-key credentials scoped to a relying party, as described by the W3C WebAuthn Level 3 Recommendation.
As an Amazon Associate I earn from qualifying purchases.
This approach is useful for exercising application registration and assertion flows in a controlled test. It does not prove that a physical security key or production authenticator works. The examples below use the Selenium Python API; do not assume that argument names or command availability are identical across language bindings or every Selenium 4 release.
Recommended Free Tools
Which commands and options matter
Authenticator lifecycle
driver.add_virtual_authenticator(options)attaches a configured virtual authenticator to the driver.authenticator.add_credential(credential)adds a credential to it.authenticator.get_credentials()returns its stored credentials.authenticator.remove_credential(credential_id)removes one credential.authenticator.remove_all_credentials()clears its credentials.driver.remove_virtual_authenticator()removes the authenticator. Once removed, it is invalid; do not call methods on it afterward.
Options should match the behavior you need to test
The Python options include protocol (ctap2 or ctap1/u2f), transport, resident-key support, user-verification support, user-consent behavior, and user-verified state. Credential properties can include the credential ID, relying-party ID, resident status, user handle, private key, and signature count. Choose these to match the relying party’s scenario rather than treating one configuration as universally best. For the documented Python API, see Selenium’s virtual authenticator reference.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Python example: register, inspect, and clean up
This example shows the test lifecycle. It assumes the test application has a registration control and reports success in an element with ID registration-status; replace the URL, locator, and assertion with those used by your application. It uses Selenium’s Python virtual-authenticator options and credential APIs. Install Selenium and a compatible browser driver for your environment; verify the API and browser support for the versions you run.
from selenium import webdriver
from selenium.webdriver.common.by import By
from selenium.webdriver.common.virtual_authenticator import (
VirtualAuthenticatorOptions,
Credential,
)
options = webdriver.ChromeOptions()
driver = webdriver.Chrome(options=options)
authenticator = None
try:
authenticator_options = VirtualAuthenticatorOptions()
authenticator_options.is_user_verified = True
authenticator = driver.add_virtual_authenticator(authenticator_options)
driver.get("https://example.test/account/security")
driver.find_element(By.ID, "register-passkey").click()
# Replace this condition with the application's actual success signal.
status = driver.find_element(By.ID, "registration-status")
assert "registered" in status.text.lower()
credentials = authenticator.get_credentials()
assert credentials, "The registration flow did not create a credential"
# Optional: remove one credential when the test scenario requires it.
# authenticator.remove_credential(credentials[0].id)
finally:
if authenticator is not None:
driver.remove_virtual_authenticator()
driver.quit()
The click and success assertion are application-specific; the virtual authenticator does not register a credential by itself. The registration page must invoke WebAuthn, and the test should assert the outcome meaningful to the application as well as any authenticator state it needs to inspect.
Preload a credential for an authentication test
For a sign-in scenario that expects an existing credential, construct a Credential using the fields required by the Selenium Python version in use, then add it before navigating to the sign-in flow. Credential details such as a private key, credential ID, relying-party ID, user handle, resident status, and signature count must be internally appropriate for the test; do not copy placeholder values into a real test. Consult the version-matched Python API reference for constructor arguments. The relying-party page still initiates WebAuthn authentication.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Choose a configuration by test scenario
| Scenario dimension | What to configure | Why it matters |
|---|---|---|
| Protocol | CTAP2 or CTAP1/U2F | Simulates the protocol behavior the relying party needs to support. |
| Transport | For example, USB or internal, where exposed by the binding | Lets a test exercise assumptions tied to how an authenticator is presented. |
| Resident/discoverable credentials | Set resident-key support and credential resident status as required | Tests flows that depend on discoverable credentials rather than only a server-provided credential identifier. |
| User verification | Configure support and user-verified state to reflect the scenario | Distinguishes a test that can satisfy a verification requirement from one that cannot. |
| User consent | Set the relevant consent behavior in options | Allows the test to model the authenticator behavior expected by the flow. |
These are simulation choices, not claims about the behavior of every real key. Match them to the relying party’s tested requirements and verify option names against the Selenium binding/version in use.
Clean up credential and authenticator state
Use remove_credential(credential_id) when a test needs to delete one credential, or remove_all_credentials() when it needs to clear the authenticator while keeping it available. After assertions, call driver.remove_virtual_authenticator() as part of teardown. The authenticator becomes invalid at that point, so do not query or modify it afterward. A finally block, as in the example, helps ensure teardown runs when an assertion or interaction fails.
Troubleshooting
The WebAuthn flow does not create a credential
Check that the test clicked the application’s registration path and that the page called WebAuthn. Adding an authenticator only configures the test device; it does not cause the page to register a credential. Assert the application’s own success signal and inspect stored credentials if appropriate.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
A command or option is missing
Confirm that the code uses the API documented for the installed Selenium Python version and that the selected driver/browser supports the virtual-authenticator operation. The cited references do not establish a universal compatibility matrix across browsers, bindings, and releases; avoid assuming support based solely on the major version number.
Calls fail after teardown
Do not use an authenticator object after calling remove_virtual_authenticator(). Finish credential inspection and cleanup operations first, then remove it.
The test passes but does not validate a physical authenticator
A virtual authenticator is software-based test infrastructure. If the requirement concerns a real hardware key, this workflow alone does not establish hardware compatibility; plan a separate hardware test.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What Chrome DevTools adds as a manual reference
Chrome DevTools documents a comparable manual workflow: enable its WebAuthn virtual-authenticator environment, add an authenticator, register through a WebAuthn page, inspect credential IDs, user handles, and sign counts, then remove the authenticator. That is useful for understanding the lifecycle, but Selenium code should follow Selenium’s own API rather than DevTools command names. See the Chrome DevTools WebAuthn documentation.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server, not a WebAuthn authenticator and not a replacement for Selenium’s credential testing. If your adjacent task is capturing a rendered page, a single request can return an image or PDF:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
See the ScreenshotNeo API documentation. It removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots, and 1,000 screenshots a month are free without a card; paid plans start at $5 for 3,000. Learn more at ScreenshotNeo. Sign up for free.
Frequently Asked Questions
Can Selenium’s virtual authenticator bypass a website’s login?
No. It supplies simulated WebAuthn authenticator behavior for a test; the application still runs its registration or authentication flow and server-side checks.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Does this prove a physical security key works?
No. A virtual authenticator is software-based and does not establish compatibility with real hardware.
Can I use the same API calls in every Selenium language binding?
Do not assume so. The detailed example here is for Selenium Python; check the documentation for the binding and version you use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




