FIDO2 / WebAuthn
FIDO2/WebAuthn: Attestation, Metadata Service (MDS3) and Trust

FIDO2 / WebAuthn FIDO2-MetadataService-MDS: FIDO Metadata Service v3 (MDS3) - AAGUID Trust + Status Reports

FIDO Metadata Service v3 (MDS3) provides the metadata + trust + status for FIDO authenticators. ENDPOINT: https://mds.fido.org/ + signed metadata BLOB updated regularly. METADATA STATEMENT contents per AAGUID: AAGUID; description; authenticator + protocol family (FIDO_2_1 + U2F + UAF + etc.); upv (Universal Authenticator Framework Protocol Versions); authenticationAlgorithms; publicKeyAlgAndEncodings; attestationTypes (BASIC + SELF + ATT_CA); userVerificationDetails; keyProtection (HARDWARE + SECURE_ELEMENT + TEE + SOFTWARE); matcherProtection; attachmentHint; isKeyRestricted; isFreshUserVerificationRequired; cryptoStrength; tcDisplay; attestationRootCertificates; ecdaaTrustAnchors; icon. STATUS REPORTS per AAGUID: NOT_FIDO_CERTIFIED; FIDO_CERTIFIED + FIDO_CERTIFIED_L1 + L2 + L3 + L3+; USER_VERIFICATION_BYPASS (security alert); ATTESTATION_KEY_COMPROMISE; USER_KEY_REMOTE_COMPROMISE; USER_KEY_PHYSICAL_COMPROMISE; UPDATE_AVAILABLE; REVOKED; SELF_ASSERTION_SUBMITTED. RP CONSUMPTION: download + verify signed MDS3 BLOB (signed by FIDO Alliance root); cache + refresh periodically; query by AAGUID at registration; ENFORCE policies based on certification + status reports.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIDO2/WebAuthn: Attestation, Metadata Service (MDS3) and Trust

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.