FIDO2/WebAuthn: Authenticators, Passkeys and User Verification
FIDO2 / WebAuthn FIDO2-Passkey-Discoverable: Passkeys (Discoverable Credentials) and Account Recovery
Discoverable credentials (formerly Resident Credentials) per WebAuthn L3 6.3 + CTAP2.1 are credentials whose private-key + per-credential metadata (rpId + userHandle + signCount) are stored on the authenticator. The user-handle enables AUTHENTICATION WITHOUT USERNAME - the RP can call navigator.credentials.get() without allowCredentials + the authenticator presents matching credentials to the user for selection. PASSKEYS: marketing name for FIDO2 discoverable credentials that ALSO support multi-device sync. Apple iCloud Keychain (2022) + Google Password Manager (2023) + Microsoft Windows Hello + 1Password + Bitwarden + Dashlane support passkey synchronisation across user devices. BACKUP ELIGIBILITY (BE) + BACKUP STATE (BS) FLAGS in authenticatorData: BE indicates the credential CAN be backed up; BS indicates the credential IS currently backed up. RP USE: BE+BS=11 indicates a synced passkey; BE=0 indicates a single-device credential (security key). Account recovery: passkey sync provides recovery via account sync; single-device credentials require enrolment of multiple authenticators OR recovery code OR identity-verification reset. EXPORT/IMPORT: in 2024-2025 FIDO Alliance is developing credential-exchange-protocol (CXP) for cross-platform passkey portability; until CXP is broadly available, passkeys are typically locked to a single platform's sync ecosystem (Apple to Apple + Google to Google).
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 48 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.