Web Authentication Level 3 became a World Wide Web Consortium (W3C) Recommendation on August 25. Level 2 is what made passkeys possible. Level 3 is what made them practical: related origin requests, so one credential can serve a company's several domains. JSON parsing for the registration and sign-in options, which removes the encoding code every implementation used to carry. Signal methods that let a site tell the authenticator a credential was deleted or a user's details changed, so the passkey list on the device stops drifting from the account. A way to ask what the client supports.
I think the significance for a web team is that the last platform reason to defer login modernization has gone. For a few years, passkeys were a thing to wait on: the spec was moving, browser support was uneven, the JSON handling was fiddly. None of that is true anymore. Every major browser implements Level 3, the text is final, and the features that made enterprise deployment awkward are in the standard.
What remains is not platform work. It is product and support work. What happens when someone loses the device. How account recovery works without a password to fall back to. What the enterprise policy is for shared machines. Those are harder questions than the integration, and they are the ones a team can no longer put off by pointing at the spec.
What is actually blocking passkeys on your product, and is it still a technical reason?
Photo source: https://photos.robertstowe.com/wieliczka-salt-mine

