CTAP2 PIN/UV authentication establishes user verification + permission tokens. PIN: 4-63 ASCII character minimum (CTAP2.1 setMinPINLength may force higher); the PIN is hashed + key-derived locally on the authenticator + used in PIN/UV Auth Protocol exchanges; PIN-CHANGE + PIN-RETRIES with throttling + lockout (typically 8 attempts before factory reset). PIN/UV AUTH PROTOCOL: ECDH key exchange between client + authenticator + a derived shared secret + token-based permission scope (mc + ga + bi + cm + cv + acfg); pinUvAuthToken is returned with selected permission set + lifetime + used to authorise subsequent commands without re-prompting. BIOMETRIC UV: authenticator-internal biometric (fingerprint + face + iris) replaces or augments PIN; biometric template never leaves authenticator; UV result returned to client. UV REQUIREMENT in WebAuthn: required = UV must succeed; preferred = UV requested but registration/auth proceeds without; discouraged = UV not requested. NIST SP 800-63B AAL3 typically requires UV=required + presence-only insufficient.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.