Every WebAuthn refusal answered "that passkey could not be verified" and discarded the library's error, leaving a misconfigured relying party undiagnosable. Log the stage, the derived RP ID and expected origin, the request's Origin and X-Forwarded-Proto, and the library error with its DevInfo. None of it is secret.