At the moment the BrowserID team provides a Javascript shim but the goal is that it will be supported natively in the browsers. The shim if a fallback (which applies for all browsers atm).
Even if the API is supported natively in the browser, it's still a JavaScript API, so you still need to allow the website to run JavaScript so that it can call that native method.