AM & Access

FIDO2 / WebAuthn

A public-key authentication standard where the private key never leaves the user's device or security key — the phishing-resistant foundation passkeys are built on.

aka: FIDO2, WebAuthn, CTAP

WebAuthn binds a credential to the origin that registered it, so the browser itself refuses to send it to the wrong domain — the phishing resistance comes from the protocol, not user vigilance. It’s the vanguard standard the article series’ history of authentication protocols builds toward, and the base layer passkeys sync across a user’s devices.