FIDO2, WebAuthn, and Passkey: What’s the Difference?

FIDO2, WebAuthn, and Passkey What's the Difference-1200

FIDO2, WebAuthn, and Passkey: What's the Difference?

These three terms are often used together, and sometimes interchangeably. They are related, but they refer to different things. Understanding the distinction helps when evaluating products or reading vendor documentation.

FIDO2

FIDO2 is an authentication standard developed by the FIDO Alliance and W3C.
It defines how passwordless and phishing-resistant authentication should work.
FIDO2 is composed of two components: WebAuthn, which handles communication between the browser and the server, and CTAP, which handles communication between the browser and the authenticator device.

WebAuthn

WebAuthn is the web API that enables browsers and applications to request authentication using a FIDO2-compatible device. It is supported by all major browsers including Chrome, Firefox, Safari, and Edge. When a service supports passwordless login, it is using WebAuthn to do so.

Passkey

Passkey is not a standard. It is a term introduced by Apple, Google, and Microsoft to describe FIDO2 credentials in more accessible language. All passkeys are FIDO2 credentials. The difference is where the credential is stored. A synced passkey is stored in a cloud account such as iCloud Keychain or Google Password Manager and can be used across multiple devices. A device-bound passkey is tied to a specific hardware authenticator such as a security key and cannot be copied or transferred.

How they relate

For most users, both passkeys and security keys provide a passwordless login experience. The distinction is in portability and security assurance. Synced passkeys are convenient but depend on the security of the cloud account they are stored in. Hardware security keys store the credential on the device itself, which is why they are required in higher-assurance environments and enterprise compliance frameworks.

FIDO2, WebAuthn, and Passkey: What's the Difference? Q&A

A:Yes. All passkeys are FIDO2 credentials. Passkey is simply the consumer-facing term introduced by Apple, Google, and Microsoft.

A:A synced passkey is stored in a cloud account and can move between devices. A hardware security key stores the credential on the device itself and cannot be copied.

A:No. Passkeys can also be stored in a cloud account such as iCloud Keychain or Google Password Manager.

A:A standard. WebAuthn is the web API that enables browsers and applications to use FIDO2 authentication.

A:A hardware security key offers a higher assurance level because the credential is physically isolated and cannot be extracted.

訂閱偉康科技洞察室部落格,掌握最新科技趨勢!

專人協助

由偉康業務人員為您詳細說明偉康的解決方案,以及相關產業經驗。

立即訂閱電子報

掌握最新科技趨勢!