How to Disable the Web Authentication Prompts in Chrome

The Hardware Key Intrusion

Web Authentication (WebAuthn) is a modern security standard that allows websites to use hardware security keys (like YubiKeys) or built-in biometric scanners (like Windows Hello or Touch ID) for passwordless logins. While highly secure, it can be incredibly irritating if you do not use these features. On certain websites, Google Chrome will aggressively pop up a large, unprompted dialogue box demanding that you “Insert your security key” or “Touch your fingerprint sensor” just because the website’s backend code triggered the API, blocking your view of the page until you manually dismiss the prompt.

Silencing the WebAuthn API

To stop websites from triggering these hardware prompts and force Google Chrome to ignore WebAuthn requests, you must disable the underlying API flag within the browser’s hidden settings.

Open a new tab in Google Chrome, type exactly chrome://flags into the address bar, and press Enter to open the experiments dashboard. In the search box at the top of the screen, type Web Authentication or simply WebAuthn. You will likely see several related flags, but you are looking for the core enablement flags, such as Web Authentication API or specific conditional UI flags like Web Authentication Conditional UI. Click the dropdown menu next to the relevant flag (which will likely be set to “Default”) and change it to Disabled. A blue “Relaunch” button will appear at the very bottom of the window. Click it to restart the browser. From this point forward, Chrome will block websites from summoning the intrusive hardware security key prompts.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.