FIDO2 / WebAuthn
FIDO2/WebAuthn: Authenticators, Passkeys and User Verification

FIDO2 / WebAuthn FIDO2-UserVerification: User Verification (UV) - PIN, Biometrics and Multi-Factor Inside Authenticator

User Verification (UV) confirms the user is present + intended the operation. UV factors local to authenticator: PIN (4-63 ASCII + CTAP2.1 setMinPINLength enforcement); BIOMETRIC (fingerprint + face + iris + voice + behavioural - all template-local-to-authenticator never transmitted); PRESENCE-ONLY (UP flag indicates physical interaction like button press without authentication of identity). UV FLAGS in authenticatorData: UP (user presence) - physical interaction; UV (user verified) - identity verified via PIN or biometric. RP UV REQUIREMENT: required = UV flag MUST be set; preferred = UV flag SHOULD be set if authenticator supports; discouraged = UV flag MAY be set but not required. PIN/UV AUTH PROTOCOL: clients obtain pinUvAuthToken with specific permission scope (mc/ga/bi/cm/cv/acfg) for authenticator commands. NIST SP 800-63B coordination: AAL2 typically presence-only sufficient; AAL3 phishing-resistant requires UV + cryptographic authenticator. BIOMETRIC FALSE-ACCEPT-RATE (FAR) policy: PCI DSS biometric ATM requires FAR less than 1 in 10K; FIDO biometric component certification programmes test FAR + FRR + presentation attack detection (PAD).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIDO2/WebAuthn: Authenticators, Passkeys and User Verification

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.