What Is FIDO2? The Standard Behind Passkeys
FIDO2 is the open authentication standard that makes passkeys and hardware security keys work, using public-key cryptography instead of shared secrets.
FIDO2 is an open authentication standard, developed by the FIDO Alliance together with the W3C, that replaces passwords with public-key cryptography verified by a physical device — a phone, a hardware security key, or a computer’s built-in security chip. It’s the underlying technical standard that makes both passkeys and dedicated hardware security keys work; passkeys are essentially FIDO2 credentials with a friendlier name and cloud sync built on top.
The two halves of FIDO2
FIDO2 is actually a pairing of two specifications that work together:
- WebAuthn (Web Authentication API), a W3C standard that defines how a browser or app talks to an authenticator to create and use credentials — the JavaScript-level API a website calls to register or verify a user.
- CTAP (Client to Authenticator Protocol), which defines how the browser or operating system talks to the physical authenticator itself, whether that’s a USB security key, a phone over Bluetooth, or a platform authenticator built into the device.
WebAuthn handles the website-to-browser side; CTAP handles the browser-to-hardware side. Together they cover the full path from “a site asks you to sign in” to “a physical device proves who you are.”
How the credential actually works
FIDO2 authentication is built on a public/private key pair generated locally on the authenticating device, one pair per site:
- Registration. When you enroll with a site, the authenticator generates a new key pair. The private key never leaves the device — it’s typically sealed inside a secure hardware element and can’t be exported even by the device’s own operating system. The public key is sent to the site and stored against your account.
- Authentication. When you sign in, the site sends a random challenge. The authenticator signs it with the private key, after confirming it’s really you — a fingerprint, a face scan, a device PIN, or simply the physical presence of tapping a hardware key. The site verifies the signature against the public key it stored at registration.
Because the private key never leaves the device and never transits the network, there’s no shared secret for an attacker to steal from a server breach, and nothing for a user to be tricked into typing into a fake login page. A credential registered for bank.example.com simply won’t produce a valid signature for a phishing site at bank-example.com — the origin is bound into the cryptographic challenge, which is what makes FIDO2 phishing-resistant by construction rather than by user vigilance.
FIDO2 vs older two-factor methods
| Passwords + SMS/TOTP codes | FIDO2 | |
|---|---|---|
| What’s transmitted at login | A password, and a one-time code | A cryptographic signature, no shared secret |
| Phishing resistance | Low — both can be typed into a fake site | High — origin-bound, unusable on the wrong domain |
| Server-side breach risk | Password hashes and phone numbers stored, exploitable if leaked | Only public keys stored — useless to an attacker without the private key |
| User friction | Remember a password, then retrieve a code | Biometric or PIN unlock, or a key tap |
| Works across devices | Manually, by reusing the same password | Via platform sync (passkeys) or by carrying a portable hardware key |
FIDO2 doesn’t just add a second factor on top of a password — in its passwordless mode, it replaces the password outright, which is the deployment path passkeys use by default.
Roaming vs platform authenticators
FIDO2 credentials can live in two different kinds of authenticator:
- Platform authenticators are built into a device — the secure enclave in a phone or laptop — and are what most passkey implementations use. Convenient, but tied to that device’s platform ecosystem unless synced through a cloud keychain.
- Roaming authenticators are separate hardware, most commonly a USB or NFC security key, that can be carried between devices and used to authenticate anywhere the physical key is present. These are the standard choice for high-security environments where a shared, device-independent credential is preferable to relying on any one device’s sync ecosystem.
Many organizations that require multi-factor authentication for privileged accounts issue roaming FIDO2 keys specifically because they’re portable, phishing-resistant, and don’t depend on a phone being unlocked, charged, or in signal range.
Why it matters beyond passkeys
Passkeys have made FIDO2 visible to ordinary consumers, but the standard predates the passkey branding by years and is used far more broadly — as the backbone of hardware security key programs at companies with strict internal security requirements, and as the mechanism behind “sign in with your device” flows that never mention FIDO2 by name. Any time a login flow offers a fingerprint, face scan, or physical key tap instead of a password, it’s very likely FIDO2 underneath, whether or not the product calls it a passkey.
The takeaway
FIDO2 is the open standard — WebAuthn plus CTAP — that makes passwordless, phishing-resistant login possible, using a locally generated key pair instead of a password or shared secret sent over the network. Passkeys are FIDO2 credentials with cloud sync layered on for convenience; hardware security keys are FIDO2 credentials that stay on dedicated, portable hardware instead. Either way, the private key never leaves the device, and the origin-binding built into the protocol is what makes it resistant to phishing in a way that passwords and one-time codes simply aren’t.
Tagged
Keep reading
The Lycoris Team · · 5 min read Biometric Authentication Explained
Biometric authentication verifies identity using fingerprints, faces, or other traits — here's how enrollment, matching, and liveness checks work.
Chisato · · 4 min read What Is a Man-in-the-Browser Attack?
A man-in-the-browser attack uses malware inside the browser itself to alter what a user sees and submits, bypassing HTTPS and session protections entirely.
The Lycoris Team · · 5 min read CSRF vs. XSS: What's the Difference?
CSRF forges a request using a victim's login session; XSS runs the attacker's own code inside the victim's browser. Different mechanisms, different fixes.