Passkey not offered on self-managed GitLab since extension 8.12.36 (Chrome shows its own dialog, NotAllowedError)
Environment
- 1Password for Linux 8.12.36, browser extension 8.12.36.40 (stable)
- Google Chrome 153.0.8010.36, Ubuntu 22.04
- Self-managed GitLab EE 19.3.1
- Business account; passkey saved in a Login item (username + passkey + one-time password)
Problem
Since the extension updated to 8.12.36 (universal sign-in) on Sept 9, 2026, 1Password no longer handles the passkey on our self-managed GitLab. Both the 2FA page after SAML SSO and the passwordless page (/users/passkeys/sign_in) behave the same way: no "Use passkey" prompt from 1Password. Instead Chrome shows its native "Use a saved passkey for gitlab.example.com" dialog (only "phone or tablet" / "USB security key"), and sign-in fails with NotAllowedError. The universal sign-in prompt at the top of the page only offers password logins.
What still works
- Passkeys for Google and Cloudflare through 1Password, in the same Chrome profile.
- On the same GitLab origin, this minimal call from the DevTools console is answered by 1Password with the correct passkey:
navigator.credentials.get({ publicKey: { challenge: new Uint8Array(32) } })
So the item, the account and the origin look fine. Only GitLab's real request falls back to Chrome.
What GitLab sends (webauthn-ruby 3.4.3, the legacy U2F appid extension is now added to every request)
- 2FA: { challenge, timeout: 120000, allowCredentials: [{ type: "public-key", id }], userVerification: "discouraged", extensions: { appid: "https://gitlab.example.com" } }
- Passwordless: { challenge, timeout: 120000, allowCredentials: [], userVerification: "required", extensions: { appid: "https://gitlab.example.com" } }
Already tried
- Turned off "Use the new autofill experience for sign in": no change.
- "Offer to sign in with passkeys" is on, the hidden pages list is empty, no other password manager extensions installed.
- Updated the desktop app and Chrome.
Note: our GitLab was upgraded from 18.9.3 to 19.3.1 one day earlier (Sept 8). On 18.9.3 the 2FA request already included extensions.appid, and the passkey worked as GitLab 2FA before these updates.
Is this a known issue with universal sign-in and WebAuthn requests that include allowCredentials and/or the appid extension? Is there a way to get the previous passkey prompt back until it's fixed?
