CTAP2 transports define how the client communicates with the authenticator. USB-HID: USB Human Interface Device class for security keys (YubiKey + Token2 + Feitian + SoloKeys + Trezor + others); FIDO2 HID protocol with CTAPHID frames. NFC: ISO 14443 Type A/B for NFC-capable security keys + phones acting as authenticators; CTAPNFC protocol. BLE-ROAMING: Bluetooth Low Energy GATT service profile for roaming authenticators; FIDO BLE service UUID 0xFFFD. HYBRID TRANSPORT (formerly caBLE - Cloud Assisted BLE): cross-device authentication via QR code + BLE proximity proof + cloud-mediated key exchange; the desktop browser displays a QR code containing a tunnel server URL + the phone scans + executes the FIDO2 ceremony on the phone + relays the assertion back via BLE proximity + tunnel server; specified in CTAP2.2 + WebAuthn L3 hints. PLATFORM-INTERNAL: built-in platform authenticators (Touch ID + Face ID + Windows Hello + Android Biometric Prompt) accessed via OS-internal APIs not CTAP HID; treated as authenticatorAttachment=platform in WebAuthn.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.