FIDO2
What is FIDO2?
FIDO2An open authentication standard from the FIDO Alliance combining WebAuthn (browser API) and CTAP (authenticator protocol) to enable phishing-resistant, passwordless sign-in.
FIDO2 is the umbrella term for two complementary specifications: WebAuthn, a W3C JavaScript API (Level 1 became a Recommendation in March 2019, Level 2 in April 2021) that lets relying parties create and verify public-key credentials, and the Client to Authenticator Protocol (CTAP), which lets browsers talk to roaming authenticators over USB, NFC, or Bluetooth. CTAP2 is the FIDO2 protocol; the older CTAP1 is simply U2F, giving FIDO2 backward compatibility with existing security keys.
At registration the authenticator generates an ECDSA (ES256/P-256) or EdDSA key pair scoped to the relying-party origin and returns the public key plus an attestation statement. At authentication the server sends a random challenge; the private key — released only after user presence and verification (touch, biometric, or PIN) — signs the challenge together with the origin. Because signatures are bound to the true origin and never leave the device, FIDO2 structurally defeats phishing, credential replay, and credential stuffing; a monotonic signature counter also flags cloned authenticators. It supports both second-factor and fully passwordless flows and is the technical basis for passkeys, the synced/discoverable credentials that Apple, Google, and Microsoft began shipping in 2022.
flowchart LR A[User visits site] --> B[Server sends random challenge and RP ID] B --> C[Browser via WebAuthn calls authenticator] C --> D[User verifies: touch, biometric, or PIN] D --> E[Private key signs challenge plus origin] E --> F[Server verifies signature with stored public key] F --> G[Access granted]
● Examples
- 01
Registering a YubiKey 5 as a second factor on a GitHub account.
- 02
Passwordless sign-in to Microsoft Entra ID with a platform authenticator on Windows Hello.
● Frequently asked questions
What is FIDO2?
An open authentication standard from the FIDO Alliance combining WebAuthn (browser API) and CTAP (authenticator protocol) to enable phishing-resistant, passwordless sign-in. It belongs to the Identity & Access category of cybersecurity.
What does FIDO2 mean?
An open authentication standard from the FIDO Alliance combining WebAuthn (browser API) and CTAP (authenticator protocol) to enable phishing-resistant, passwordless sign-in.
How do you defend against FIDO2?
Defences for FIDO2 typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for FIDO2?
Common alternative names include: FIDO 2.0.