# fido2

Source: https://startwithidentity.com/glossary/fido2/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

FIDO2 is a set of specifications from the FIDO Alliance plus W3C. It combines WebAuthn (the browser API) with CTAP (the client-to-authenticator protocol) to enable phishing-resistant authentication using hardware or platform authenticators.

FIDO2 is the standards base under every passkey. The security property that matters is origin binding: the authenticator will only produce a signature for the site that registered the credential, so a proxy phishing page cannot obtain a usable assertion no matter how convincing it looks. That single property defeats the attacker-in-the-middle kits that relay one-time codes and push approvals at scale.

See also: [WebAuthn and FIDO2](https://startwithidentity.com/standards/webauthn-fido2/), [passkey](https://startwithidentity.com/glossary/passkey/), [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/), [add passkeys with WebAuthn recipe](https://startwithidentity.com/recipes/add-passkeys-webauthn/)
