Passkey spike
Proving one claim before any of this ships: that the browser will hand the server a usable public key, so nothing has to parse CBOR. Nothing here is saved — it all lives in memory and goes when the server restarts.
Use different names to keep devices apart, or the same name on several devices to test more than one passkey on one account.
Sign in with it names the key we stored. Any passkey on this device asks the system for whatever it can find — which some browsers answer differently, and is the thing worth trying when the first one fails.
What to ask the device for
Change one at a time, register a fresh passkey, then try both sign-in buttons. Every attempt is logged with the combination used, so the table below becomes the answer.
What this browser supports
Every attempt, newest first
This is the actual deliverable: which devices worked, which did not, and what they said. Try a phone, a laptop, 1Password, and Safari as well as Chrome.