What Is U2F (Universal 2nd Factor)?

Also called: FIDO U2F, Universal Second Factor

Related problems: Old security keys and not sure if they still work; Deciding whether to replace U2F-only keys with FIDO2 keys; App or VPN only supports U2F-style security keys

Universal 2nd Factor (U2F) is an open standard, published by the FIDO Alliance, that lets a user add a physical security key as a second factor after their password. When the user signs in, the key signs a challenge from the website with a key pair created for that site, after the user touches the key. U2F was the first widely adopted FIDO standard and is the foundation that FIDO2 builds on; within FIDO2’s Client to Authenticator Protocol (CTAP), the U2F protocol is known as CTAP1.

At a glance

  • A second-factor standard: password first, then a touch on a hardware security key.
  • Public-key based and bound to the site’s origin, so it was one of the first widely used phishing-resistant second factors.
  • Checks user presence (a touch) but not user verification; there is no PIN or biometric in the U2F protocol.
  • FIDO2 succeeded it for new work; CTAP2 keys are recommended to also support U2F, and browsers use U2F keys through WebAuthn.
  • Superseded by FIDO2 for new work; kept in CTAP (as CTAP1) and in most current keys for compatibility.

What problem it solves

When U2F appeared, the common second factors were SMS codes and code-generating tokens, both of which a fake login page can capture and replay. U2F replaced the typed code with a signature from a key the user physically holds, tied to the domain of the real website. A phishing site on a different domain gets no valid response, and the website stores only a public key, not a shared secret.

It also made security keys inexpensive and interchangeable: one key could be registered with many unrelated services, and the protocol was designed so those services can’t easily link the registrations to each other.

How it works

Registration. After signing in with a password, the user adds a key. The website sends a challenge and its application identity; the browser adds the origin and passes the request to the key over USB, NFC or Bluetooth. The key generates a new key pair for that site and returns the public key and a key handle. The response may also include attestation data, which the website can validate against trusted vendor or FIDO Alliance metadata to identify or restrict key models; attestation certificates can be self-signed or untrusted, so they identify a model only when the website checks them.

Authentication. At each sign-in, after the password, the site sends a challenge and the stored key handle. The user touches the key to confirm presence, and the key signs the challenge, including the origin the browser reported, with the site’s private key. A counter in the response helps the site detect cloned keys.

Credentials not stored on the key. U2F keys typically don’t keep a list of sites. The website keeps the key handle and sends it back at sign-in, which is why U2F works as a second factor after a username, not as a passwordless sign-in.

Relationship to FIDO2. FIDO2’s CTAP specification defines two protocol versions: CTAP1, which is U2F, and CTAP2. CTAP2 adds user verification (PIN or biometric), discoverable credentials stored on the key, and support for passwordless sign-in and passkeys. The browser side moved from the old U2F JavaScript API, which major browsers have retired, to WebAuthn, which can still use U2F keys and credentials registered with them.

When it matters for buyers

  • When you have older keys in a drawer. U2F-only keys can usually still serve as a second factor, but not for passwordless sign-in or passkeys.
  • When buying new keys. Buy FIDO2-capable keys; most support U2F as well, which keeps older systems working.
  • When an application only supports U2F. Some older applications and VPNs built on U2F before FIDO2 existed. Check whether they now use WebAuthn, or put them behind an identity provider that does.
  • For phishing-resistant MFA policies. Confirm whether your identity provider and policy wording accept U2F-style registrations or require FIDO2 with user verification.

Questions to ask vendors

  • Do you accept U2F-only security keys, or only FIDO2 authenticators?
  • Have you moved from the legacy U2F API to WebAuthn, and do existing U2F registrations still work?
  • Can we require user verification (PIN or biometric), which U2F keys can’t provide?
  • Which key models are on your tested or approved list?
  • How do users with U2F keys migrate to FIDO2 keys or passkeys without losing access?

How it differs from FIDO2

U2F covers one job: a security key as a second factor, confirmed by a touch. FIDO2 is the broader, newer set of standards. It keeps U2F compatibility through CTAP1, but adds user verification, credentials stored on the authenticator, built-in authenticators in phones and laptops, cross-device sign-in and a standard web API. For new purchases and policies, FIDO2 is the target; U2F matters mainly for compatibility with keys and systems you already have. For protecting administrator accounts with security keys, see our privileged access management overview.

Frequently Asked Questions

Is U2F still supported?
U2F keys generally still work as a second factor. Browsers have moved from the old U2F JavaScript API to WebAuthn, which can use U2F keys, and CTAP includes the U2F protocol as CTAP1. Support in a specific application or identity provider should be checked rather than assumed.
What is the difference between U2F and FIDO2?
U2F is a second factor only: a password first, then a touch on the key. FIDO2 adds PIN or biometric verification on the authenticator, credentials stored on the key, passwordless sign-in and passkeys, plus a standard web API (WebAuthn).
Should we replace U2F-only keys?
If you want passwordless sign-in, passkeys on security keys or PIN-protected keys, yes, because U2F-only keys can't do those. If they are used only as a second factor and your systems still accept them, replacement can follow your normal refresh cycle.
Is U2F phishing-resistant?
It was designed to be: the key signs a response tied to the site's origin, so a look-alike domain gets nothing usable. Like any method, it can be undermined if weaker fallbacks or loose account recovery remain available.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.