WebAuthn is the web-facing API, CTAP is how a computer can communicate with an external authenticator, and FIDO2 is the broader pairing of WebAuthn and CTAP. U2F is the earlier FIDO second-factor protocol, carried forward as CTAP1. A physical security key is one kind of authenticator—not a requirement for every FIDO2 sign-in.
How the terms fit together
These names refer to different parts of the authentication system, not interchangeable products. The W3C defines WebAuthn as a web API for creating and using public-key credentials. CTAP, from the FIDO Alliance, covers communication between a platform and an authenticator, such as an external USB or NFC key. FIDO2 refers to WebAuthn together with CTAP.
| Term | What it means | What it does not mean |
|---|---|---|
| WebAuthn | The web API a site uses to request registration or authentication with a public-key credential. W3C Web Authentication | A physical security key. |
| CTAP | The FIDO protocol family for communication between a platform and an authenticator, including an external key. FIDO Alliance specifications overview | The website-facing API. |
| FIDO2 | The standards pairing of WebAuthn and CTAP. FIDO Alliance specifications overview | A particular key or device model. |
| U2F / CTAP1 | The earlier FIDO second-factor protocol, referred to as CTAP1 in the newer framework. FIDO Alliance specifications overview | A guarantee that every WebAuthn service accepts every older key. |
| CTAP2 | A newer CTAP protocol supporting authentication experiences beyond the original U2F second-factor pattern. FIDO Alliance specifications overview | A synonym for WebAuthn. |
| Security key | A physical external authenticator that may communicate with a device over USB or NFC. FIDO Alliance specifications overview | The only kind of FIDO authenticator; platform-integrated authenticators are also possible. |
A useful shorthand: WebAuthn is the request interface, CTAP is one route for a computer to talk to an external authenticator, and the key is the device that holds or uses a credential. U2F is the older second-factor route, represented in the newer terminology by CTAP1. For details of protocol operations, consult the FIDO Alliance specifications; the CTAP source available here is a 2024 review-draft snapshot, not evidence of the latest published edition.
How a security key authenticates you
Registration: create a credential for a service
A website, known as the relying party, asks the browser or platform to register a public-key credential through WebAuthn. The platform handles the request and may communicate with an external key through CTAP. The authenticator creates a credential key pair for that service; the service stores the public-key credential data.
#1 Best Overall
Sign-in: prove possession of the credential
At sign-in, the service sends a fresh challenge. The authenticator uses the private-key side of the credential to answer it, and the service checks the response against its stored public key. Depending on the authenticator and the request, the user may need to touch the key, enter a PIN, or use a local biometric. Exact steps vary by platform and authenticator.
Biometric information, when used, stays on the user’s device rather than being sent to the website, according to the FIDO Alliance. The site verifies the cryptographic result; it does not receive a fingerprint or face scan.
Rank #2
Why FIDO credentials resist phishing—and what that does not cover
FIDO credentials are unique and bound to the online service domain, according to the FIDO Alliance. A credential registered for the genuine domain cannot simply be reused by a lookalike phishing site. That domain scoping is the source of FIDO’s phishing resistance.
It is not a cure-all for account compromise. It does not by itself protect against malware or a compromised device, weak account recovery, social engineering outside the credential ceremony, or flaws in a service’s implementation. Keep recovery options secure and follow the service’s account-protection guidance.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCan an old U2F key work with WebAuthn?
It can, if the service supports U2F-compatible authenticators. FIDO describes U2F devices as CTAP1 and says existing U2F devices can work with U2F services and WebAuthn applications that support them. Compatibility therefore depends on both the key and the particular service; the label “WebAuthn” alone does not promise that every older key will be accepted. FIDO Alliance passkey information
Do you need a physical security key to use FIDO2?
No. FIDO2 includes both external or roaming authenticators, such as USB/NFC keys, and authenticators built into a platform. Whether you can use a particular option depends on the service’s sign-in choices and the device or authenticator you have.
Rank #4
How to check compatibility before choosing a key
- Check the service first. Confirm that the account supports security-key or WebAuthn sign-in, and whether it accepts the type of authenticator you plan to use.
- Match the connection. Check whether your devices accept USB-A, USB-C, NFC, or the combination offered by the key.
- Check protocol breadth. Some keys focus on FIDO authentication; others also support functions such as one-time passwords, smart-card use, or OpenPGP. Extra functions matter only if you need them.
- Plan for loss. Where a service permits it, register an appropriate backup authenticator and understand the account’s recovery process.
For illustration, Yubico lists its Security Key C NFC as a FIDO-focused USB-C/NFC option supporting WebAuthn, FIDO2 CTAP1/CTAP2/CTAP2.1, and U2F. Its YubiKey 5 NFC is a USB-A/NFC multi-protocol model that also lists OTP, PIV-compatible smart-card, and OpenPGP capabilities. These are manufacturer-listed specifications, not independent rankings; confirm current details and your service’s requirements before buying.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

