FIDO2 is a set of open authentication standards that lets people sign in with public-key cryptography instead of, or in addition to, a password. It is developed by the FIDO Alliance (from “Fast IDentity Online”), an industry association, together with the W3C, and is made up of two parts: Web Authentication (WebAuthn), the browser and platform API that websites call, and the Client to Authenticator Protocol (CTAP), which lets a computer or phone talk to an authenticator such as a hardware security key. Passkeys are built on FIDO2.
At a glance
- FIDO2 = WebAuthn (a W3C standard) + CTAP (a FIDO Alliance specification).
- Users hold a private key on an authenticator; the service stores only the matching public key, so there is no shared secret to steal from the server.
- Each credential is scoped to one site’s domain, which is what makes FIDO2 a basis for phishing-resistant MFA.
- Authenticators can be built into devices (platform authenticators) or separate (roaming), such as security keys or a phone used for cross-device sign-in.
- It extends the older Universal 2nd Factor (U2F) standard, adding PIN or biometric user verification and passwordless sign-in.
What problem it solves
Passwords and one-time codes share one weakness: whatever the user types can be typed into a fake page and replayed. Adversary-in-the-middle phishing kits do exactly that, in real time, against SMS codes, authenticator app codes and push approvals.
FIDO2 replaces typed secrets with a signature that only works for the genuine site. The browser tells the authenticator which domain is asking, and the authenticator signs only with a credential registered to that domain. A proxy on a look-alike domain gets nothing it can reuse. Because the server holds only public keys, a breach of the service’s database doesn’t expose reusable sign-in credentials either.
How it works
Registration. A user signs in and adds a FIDO2 authenticator. The website calls WebAuthn; the browser passes the request to the authenticator, built-in or over CTAP via USB, NFC, Bluetooth or a cross-device (hybrid) connection to a phone. The authenticator creates a new key pair for that site and returns the public key, optionally with attestation data, which the service can validate against trusted metadata to identify the authenticator model.
Sign-in. The site sends a random challenge. The browser adds the site’s real origin, and the authenticator checks user presence (a touch) and, where required, user verification (a PIN or biometric checked locally). It signs the challenge with the site’s private key. The site verifies the signature with the stored public key.
Second factor or passwordless. FIDO2 credentials can be used as a second factor after a password, or as a full passwordless sign-in when the authenticator verifies the user and stores a discoverable credential, which is what passkeys are.
Versions. WebAuthn is published by the W3C in levels; CTAP is published by the FIDO Alliance in numbered versions (the 2.x line), and CTAP2 authenticators are recommended to also support the older U2F protocol, known as CTAP1. Exact feature support varies by browser, operating system and key model.
Enterprise policy. Your identity provider decides whether FIDO2 is allowed, for whom, and which authenticator models it accepts, often using attestation to allow only approved keys.
When it matters for buyers
- When upgrading MFA. FIDO2 is the usual route from SMS, codes and push to phishing-resistant sign-in.
- At cyber insurance renewal. Some applications ask specifically whether MFA resists phishing; FIDO2 keys and passkeys are the common answer. Requirements vary by insurer.
- When choosing an identity provider or tier. Support for FIDO2, attestation restrictions and enforcement by group differ.
- For shared or kiosk devices. A roaming security key the user carries can work where personal phones can’t be used.
- When planning recovery. Users need a second registered key or another strong method, and re-enrollment needs strong identity checks.
- For legacy systems. Some VPNs, desktop logins and older applications don’t support FIDO2 directly and may need to sit behind the identity provider.
Questions to ask vendors
- Do you support FIDO2 security keys and passkeys for workforce sign-in, and on which license tiers?
- Can we require FIDO2 for specific users and applications and block weaker fallbacks for them?
- Do you support attestation so we can restrict accepted authenticator models?
- Which of our applications, VPN and desktop logins can use FIDO2, and which can’t?
- How are keys enrolled for new staff and replaced when lost?
- Can we report which users have FIDO2 credentials registered?
How it differs from U2F
U2F was the FIDO Alliance’s first second-factor standard: a security key added a cryptographic, domain-bound second step after a password, confirmed by a touch. FIDO2 builds on it. WebAuthn replaced the older browser API, and CTAP2 added user verification by PIN or biometric, credentials stored on the authenticator and passwordless sign-in. U2F-only keys generally still work as a second factor through WebAuthn, but not for passwordless sign-in. For managing the devices that hold FIDO2 credentials, see our unified endpoint management overview.
