User Verification (UV) confirms the user is present + intended the operation. UV factors local to authenticator: PIN (4-63 ASCII + CTAP2.1 setMinPINLength enforcement); BIOMETRIC (fingerprint + face + iris + voice + behavioural - all template-local-to-authenticator never transmitted); PRESENCE-ONLY (UP flag indicates physical interaction like button press without authentication of identity). UV FLAGS in authenticatorData: UP (user presence) - physical interaction; UV (user verified) - identity verified via PIN or biometric. RP UV REQUIREMENT: required = UV flag MUST be set; preferred = UV flag SHOULD be set if authenticator supports; discouraged = UV flag MAY be set but not required. PIN/UV AUTH PROTOCOL: clients obtain pinUvAuthToken with specific permission scope (mc/ga/bi/cm/cv/acfg) for authenticator commands. NIST SP 800-63B coordination: AAL2 typically presence-only sufficient; AAL3 phishing-resistant requires UV + cryptographic authenticator. BIOMETRIC FALSE-ACCEPT-RATE (FAR) policy: PCI DSS biometric ATM requires FAR less than 1 in 10K; FIDO biometric component certification programmes test FAR + FRR + presentation attack detection (PAD).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.