Instead of using a passkey to replicate a JSON credential between browser instances, it is possible to fuse a passkey with the JSON credential, and make the resulting passkey-fused credential available to all the browser instances controlled by the user at once.
This blog post provides a definition of a passkey-fused credential as a distributed data structure that comprises a discoverable passkey and a public key certificate. The public key of the passkey is used as the public key in the certificate, and the certificate is encrypted under a symmetric key that is included in the user.id parameter of the passkey when the credential is created, and recovered from the userHandle property of the response when the passkey is used to compute the proof-of-possession signature on the challenge and callback URL received from the relying party. Together, use of the passkey to compute the signature and encryption of the certificate provide full cryptographic protection.
Detailed definitions of the credential and specifications of the issuance and presentation protocols can be found in the blog post.
