Decode WebAuthn registration or authentication JSON, clientDataJSON, authenticator flags, sign counter, AAGUID, credential ID, and common COSE key fields.
A production relying party must verify challenge, origin, RP ID hash, user presence or verification policy, signature, algorithms, attestation policy, and sign-counter behavior.