Designed around WebAuthn, not around friction.
Verification uses the platform-standard WebAuthn API — passkeys and platform or roaming authenticators. We validate origin and relying-party ID, check the signature counter for anti-cloning, and issue single-use challenges, because the hardware-backed artifact is only meaningful if the ceremony around it is strict.