What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
FIDO means Fast Identity Online. It is a family of authentication standards built around public-key cryptography. FIDO2 combines WebAuthn, the web-facing authentication API, with CTAP, which lets devices communicate with external authenticators such as security keys. Passkeys use these FIDO standards; you do not need a separate security key to use one.
What is FIDO (Fast Identity Online)?
FIDO is an authentication standards effort from the FIDO Alliance. Instead of proving identity by sending a password to a service, FIDO authentication uses a cryptographic credential created for that service. During setup, an authenticator creates a key pair: the service keeps the public key, while the authenticator retains the private-key capability. At sign-in, the service sends a challenge and the authenticator uses its credential to prove possession.
Because credentials are specific to a service, a sign-in prompt on a lookalike phishing site cannot simply reuse the credential registered for the real site. This is the basis of FIDO’s phishing-resistant design, not a guarantee that every account is secure: the service’s implementation and its account recovery process still matter. FIDO Alliance: FIDO User Authentication Specifications
Recommended Free Tools
How do FIDO, FIDO2, WebAuthn, CTAP, and passkeys relate?
| Term | What it means |
|---|---|
| FIDO | The broader family of authentication standards and specifications from the FIDO Alliance, including U2F, UAF, and CTAP. |
| FIDO2 | The combination of WebAuthn and CTAP. |
| WebAuthn | The W3C web API that lets websites and applications use public-key credentials for authentication. |
| CTAP | The FIDO protocol that enables communication between a client device and an external authenticator. |
| Passkeys | Credentials based on FIDO standards. They use FIDO2 rather than a separate, competing standard. |
In the FIDO2 context, CTAP1 is the name for the earlier U2F protocol. UAF is another FIDO specification family; it is not another name for FIDO2. The FIDO Alliance summarizes the relationship as “FIDO2 = W3C WebAuthn + CTAP.” FIDO Alliance: The Passkey Pledge
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What happens when you sign in with a passkey?
- Registration: You choose to add a passkey on a compatible service. Your authenticator creates a service-specific credential, and the service stores its public key.
- Local approval: At sign-in, you approve the request using the device’s available unlock method, such as a fingerprint, face recognition, PIN, or device password.
- Challenge response: The authenticator uses the credential to answer the service’s sign-in challenge. The service verifies the response with the public key it holds.
If you use biometrics, the check happens locally on your device. FIDO says the service receives assurance that the check succeeded, not your biometric information. FIDO Alliance: Passkeys
Do you need a separate FIDO security key?
No. A phone or computer can act as a built-in, or platform, authenticator and use its local biometric or PIN. A hardware security key is an optional external, or roaming, authenticator. A phone can also act as an external authenticator when used with another device. CTAP supports USB, NFC, and Bluetooth Low Energy (BLE) transports for external authenticators. FIDO Alliance: FIDO User Authentication Specifications
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Whether a key or built-in authenticator is suitable depends on the service and devices you use. Before relying on either, check which sign-in methods the service accepts and whether your operating system, browser, and authenticator interface are compatible. Standards enable interoperability, but do not mean every key works with every account. FIDO CTAP 2.2 Proposed Standard
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Synced and device-bound passkeys: what is the difference?
| Type | How it works | What to consider |
|---|---|---|
| Synced passkey | Synchronization makes the passkey available across devices through a service. | Convenient when you use multiple devices; consider how you control access to the syncing account and recover it. |
| Device-bound passkey | The credential stays on one device. Security keys and devices with secure hardware are examples. | Can suit policies that require credentials to remain on a specific device, but plan for access if that device is lost or unavailable. |
Neither type is universally better. Choose based on the portability you need, how you manage devices, your organization’s policy, and what recovery options the service provides. FIDO standards do not prescribe one universal recovery method. FIDO Alliance: Passkeys
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What is the current FIDO2 standards status?
As of 7 October 2026, the FIDO Alliance reported that WebAuthn Level 3 became a W3C Recommendation on 25 August 2026; its announcement was dated 31 August 2026. A W3C Recommendation is a stable specification reference for implementers. FIDO Alliance: WebAuthn Level 3 becomes a W3C Recommendation
The FIDO specifications index lists CTAP 2.2 as a Proposed Standard, dated 14 July 2025. Separately, the Alliance’s active server certification requirements profile references WebAuthn Level 3 and CTAP 2.3. A version’s appearance in a certification profile does not by itself mean it has the same publication status as a Proposed Standard or W3C Recommendation. FIDO Alliance: FIDO specifications FIDO Alliance: Functional certification
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What to check before choosing a FIDO sign-in method
- Service support: Confirm that the account supports passkeys or the particular security key you plan to use.
- Device and browser support: Check the operating system, browser, and authenticator interface requirements for that service.
- Credential location: Decide whether cross-device access from a synced passkey or a device-bound credential fits your needs.
- Lost-device recovery: Find out how you can regain account access before you lose a phone, computer, or key. Do not assume FIDO defines the service’s recovery process.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

