FIDO Client-to-Authenticator Protocol 2.1 (CTAP2.1, FIDO Alliance Proposed Standard). The protocol between the client (operating system + browser) + authenticator devices. CTAP2.1 COMMANDS: authenticatorMakeCredential (registration); authenticatorGetAssertion (authentication); authenticatorGetInfo (capabilities + AAGUID + transports + algorithms + extensions); authenticatorClientPIN (PIN setup + change + token); authenticatorReset (factory reset); authenticatorBioEnrollment (biometric enrollment); authenticatorCredentialManagement (list + delete credentials on the authenticator); authenticatorSelection (selection between multiple authenticators); authenticatorLargeBlobs (large blob storage); authenticatorConfig (turn pinUvAuthToken on/off; setMinPINLength); authenticatorReset. CTAP2.1 features over 2.0: PIN minimum length enforcement (configurable per RP); PIN/UV authentication tokens for permission separation; large blob support; setMinPINLength configuration; enterprise attestation; AAGUID change support. CBOR encoding for all messages. Transport-bound: USB-HID + NFC + BLE-roaming (CTAP2.1) + Hybrid Transport (formerly caBLE) for cross-device + Platform-internal for built-in authenticators (Windows Hello / Touch ID / Face ID).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.