What Is FIDO2?

Also called: FIDO2 authentication

Related problems: Attackers getting past our MFA with fake login pages; Insurer or customer asking for phishing-resistant authentication; Not sure which security keys or passkeys our systems support; Want to reduce password resets and password-based attacks

FIDO2 is a set of open authentication standards that lets people sign in with public-key cryptography instead of, or in addition to, a password. It is developed by the FIDO Alliance (from “Fast IDentity Online”), an industry association, together with the W3C, and is made up of two parts: Web Authentication (WebAuthn), the browser and platform API that websites call, and the Client to Authenticator Protocol (CTAP), which lets a computer or phone talk to an authenticator such as a hardware security key. Passkeys are built on FIDO2.

At a glance

  • FIDO2 = WebAuthn (a W3C standard) + CTAP (a FIDO Alliance specification).
  • Users hold a private key on an authenticator; the service stores only the matching public key, so there is no shared secret to steal from the server.
  • Each credential is scoped to one site’s domain, which is what makes FIDO2 a basis for phishing-resistant MFA.
  • Authenticators can be built into devices (platform authenticators) or separate (roaming), such as security keys or a phone used for cross-device sign-in.
  • It extends the older Universal 2nd Factor (U2F) standard, adding PIN or biometric user verification and passwordless sign-in.

What problem it solves

Passwords and one-time codes share one weakness: whatever the user types can be typed into a fake page and replayed. Adversary-in-the-middle phishing kits do exactly that, in real time, against SMS codes, authenticator app codes and push approvals.

FIDO2 replaces typed secrets with a signature that only works for the genuine site. The browser tells the authenticator which domain is asking, and the authenticator signs only with a credential registered to that domain. A proxy on a look-alike domain gets nothing it can reuse. Because the server holds only public keys, a breach of the service’s database doesn’t expose reusable sign-in credentials either.

How it works

Registration. A user signs in and adds a FIDO2 authenticator. The website calls WebAuthn; the browser passes the request to the authenticator, built-in or over CTAP via USB, NFC, Bluetooth or a cross-device (hybrid) connection to a phone. The authenticator creates a new key pair for that site and returns the public key, optionally with attestation data, which the service can validate against trusted metadata to identify the authenticator model.

Sign-in. The site sends a random challenge. The browser adds the site’s real origin, and the authenticator checks user presence (a touch) and, where required, user verification (a PIN or biometric checked locally). It signs the challenge with the site’s private key. The site verifies the signature with the stored public key.

Second factor or passwordless. FIDO2 credentials can be used as a second factor after a password, or as a full passwordless sign-in when the authenticator verifies the user and stores a discoverable credential, which is what passkeys are.

Versions. WebAuthn is published by the W3C in levels; CTAP is published by the FIDO Alliance in numbered versions (the 2.x line), and CTAP2 authenticators are recommended to also support the older U2F protocol, known as CTAP1. Exact feature support varies by browser, operating system and key model.

Enterprise policy. Your identity provider decides whether FIDO2 is allowed, for whom, and which authenticator models it accepts, often using attestation to allow only approved keys.

When it matters for buyers

  • When upgrading MFA. FIDO2 is the usual route from SMS, codes and push to phishing-resistant sign-in.
  • At cyber insurance renewal. Some applications ask specifically whether MFA resists phishing; FIDO2 keys and passkeys are the common answer. Requirements vary by insurer.
  • When choosing an identity provider or tier. Support for FIDO2, attestation restrictions and enforcement by group differ.
  • For shared or kiosk devices. A roaming security key the user carries can work where personal phones can’t be used.
  • When planning recovery. Users need a second registered key or another strong method, and re-enrollment needs strong identity checks.
  • For legacy systems. Some VPNs, desktop logins and older applications don’t support FIDO2 directly and may need to sit behind the identity provider.

Questions to ask vendors

  • Do you support FIDO2 security keys and passkeys for workforce sign-in, and on which license tiers?
  • Can we require FIDO2 for specific users and applications and block weaker fallbacks for them?
  • Do you support attestation so we can restrict accepted authenticator models?
  • Which of our applications, VPN and desktop logins can use FIDO2, and which can’t?
  • How are keys enrolled for new staff and replaced when lost?
  • Can we report which users have FIDO2 credentials registered?

How it differs from U2F

U2F was the FIDO Alliance’s first second-factor standard: a security key added a cryptographic, domain-bound second step after a password, confirmed by a touch. FIDO2 builds on it. WebAuthn replaced the older browser API, and CTAP2 added user verification by PIN or biometric, credentials stored on the authenticator and passwordless sign-in. U2F-only keys generally still work as a second factor through WebAuthn, but not for passwordless sign-in. For managing the devices that hold FIDO2 credentials, see our unified endpoint management overview.

Frequently Asked Questions

What does FIDO stand for?
FIDO comes from Fast IDentity Online, the name of the FIDO Alliance, the industry group that publishes the standards. FIDO2 is the name of a set of specifications, not an acronym with its own expansion.
Is FIDO2 the same as passkeys?
Not exactly. FIDO2 is the set of standards. Passkey is the user-friendly name for FIDO credentials created under them, both synced passkeys in credential managers and device-bound passkeys on security keys.
Is FIDO2 phishing-resistant?
It is designed to be. Each credential is tied to the domain it was created for, and the browser reports the real domain to the authenticator, so a look-alike site gets no usable response. Weak fallback methods and account recovery can still undermine it, so they need to be locked down too.
Do our old U2F security keys work with FIDO2?
Usually, as a second factor. CTAP includes the older U2F protocol (called CTAP1), and browsers can use U2F keys through WebAuthn. U2F-only keys can't do passwordless sign-in or PIN verification, which need a FIDO2-capable key.
Does FIDO2 need special hardware?
Not always. Many current phones and computers have built-in FIDO2 authenticators unlocked by biometric or PIN. Separate hardware security keys are used where organizations want a device-bound credential, have shared devices or need a method that doesn't depend on a phone.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.