FIDO2

FIDO2 is a family of open standards for passwordless and phishing-resistant authentication developed by the FIDO Alliance and the World Wide Web Consortium (W3C). It consists of the W3C's Web Authentication API (WebAuthn) and the FIDO Alliance's Client to Authenticator Protocol (CTAP).

WebAuthn is the interface through which websites and applications in the browser or operating system initiate a cryptographic login; it has been an official W3C recommendation since 2019. CTAP governs communication with external authenticators such as USB, NFC or Bluetooth security keys. During registration, the authenticator generates a separate key pair for each service; the service stores only the public key. During login, the authenticator signs a challenge after the user has consented locally via biometrics or PIN. Its predecessor was the U2F standard, which was intended exclusively as a second factor.

Because each key pair is bound to the domain of the registered service, FIDO2 proofs cannot be used on fake pages. FIDO2 is therefore considered the reference for Phishing-Resistant MFA; the widespread form for end users is Passkeys. FIDO2 thus forms the technical basis of modern passwordless methods in Identity Security.