FIDO2 / WebAuthn
FIDO2/WebAuthn: CTAP2.1 Client-to-Authenticator Protocol

FIDO2 / WebAuthn FIDO2-CTAP2-Transport: CTAP2 Transports (USB-HID, NFC, BLE, Hybrid / caBLE, Platform-internal)

CTAP2 transports define how the client communicates with the authenticator. USB-HID: USB Human Interface Device class for security keys (YubiKey + Token2 + Feitian + SoloKeys + Trezor + others); FIDO2 HID protocol with CTAPHID frames. NFC: ISO 14443 Type A/B for NFC-capable security keys + phones acting as authenticators; CTAPNFC protocol. BLE-ROAMING: Bluetooth Low Energy GATT service profile for roaming authenticators; FIDO BLE service UUID 0xFFFD. HYBRID TRANSPORT (formerly caBLE - Cloud Assisted BLE): cross-device authentication via QR code + BLE proximity proof + cloud-mediated key exchange; the desktop browser displays a QR code containing a tunnel server URL + the phone scans + executes the FIDO2 ceremony on the phone + relays the assertion back via BLE proximity + tunnel server; specified in CTAP2.2 + WebAuthn L3 hints. PLATFORM-INTERNAL: built-in platform authenticators (Touch ID + Face ID + Windows Hello + Android Biometric Prompt) accessed via OS-internal APIs not CTAP HID; treated as authenticatorAttachment=platform in WebAuthn.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIDO2/WebAuthn: CTAP2.1 Client-to-Authenticator Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.