Authentication

    FIDO2 for Banks: What It Is and Why Banks Are Adopting It

    By TechFlex Solutions5 min read

    Passwords and one-time codes share a weakness: anything a customer can read or type, an attacker can trick them into handing over. FIDO2 removes that weakness by replacing shared secrets with public-key cryptography. This guide explains how FIDO2 works, why it resists phishing, and where it fits in a bank's authentication strategy.

    What is FIDO2?

    FIDO2 is an open authentication standard developed by the FIDO Alliance together with the World Wide Web Consortium (W3C). It has two parts:

    • WebAuthn — a W3C web standard that lets websites and apps register and authenticate users with cryptographic credentials, supported by all major browsers and operating systems.
    • CTAP (Client to Authenticator Protocol) — the protocol a browser or device uses to talk to an external authenticator, such as a security key connected over USB, NFC or Bluetooth.

    The credentials FIDO2 creates are often called passkeys. They can live on a dedicated hardware security key, or inside a phone or laptop's secure hardware.

    How FIDO2 authentication works

    FIDO2 replaces the shared secret at the heart of passwords and OTPs with a key pair:

    1. Registration. When a customer enrols, their authenticator generates a new public/private key pair just for that bank. The public key is sent to the bank. The private key never leaves the authenticator.
    2. Authentication. At login, the bank sends a random challenge. The customer confirms their presence — usually with a fingerprint, face scan, PIN or a touch of the key — and the authenticator signs the challenge with the private key.
    3. Verification. The bank checks the signature with the stored public key. If it matches, the customer is authenticated.

    Biometric data, where used, is checked locally on the device or key. It is not sent to the bank, and there is no central database of fingerprints or passwords to steal.

    Why FIDO2 resists phishing

    The defining feature of FIDO2 is origin binding. Each credential is tied to the exact web domain or app it was registered with. If a customer is lured to a look-alike phishing site, the authenticator simply has no credential for that domain and will not sign anything. There is no code to read out over the phone and nothing to type into a fake page.

    This is why security agencies and standards bodies describe FIDO-based authentication as phishing-resistant — a stronger category than MFA that relies on one-time codes, which can be relayed by an attacker in real time.

    Types of FIDO2 authenticators

    • Roaming authenticators (security keys). Small hardware devices that connect over USB, NFC or Bluetooth. Some include a fingerprint sensor so the key itself verifies the user. They work across devices and do not depend on the customer's phone.
    • Platform authenticators. Built into the device — Windows Hello, Apple Touch ID and Face ID, or Android biometrics. They need no extra hardware.
    • Synced passkeys. Credentials backed up and synchronised across a user's devices by their platform provider, which makes recovery easier at some cost in control over where the key lives.

    Why banks are adopting FIDO2

    Phishing and social engineering remain the main threat. Many banking frauds succeed not by breaking technology but by persuading customers or staff to share a code. FIDO2 removes the code.

    Regulation is moving towards stronger factors. India's 2025 authentication directions are method-neutral, leaving banks free to adopt factors beyond SMS OTP. Regulators elsewhere have gone further: the Central Bank of the UAE has directed banks to move away from SMS and email OTPs towards methods such as in-app approval and FIDO2 passkeys.

    Better customer experience. A fingerprint or a tap is faster than waiting for and typing a six-digit code, and there is no dependency on mobile network coverage.

    Lower operational cost. Fewer password resets, fewer SMS messages and fewer fraud investigations.

    Where FIDO2 fits in a bank

    • Employee and privileged access — protecting staff who access core banking, payment and administrative systems, a frequent target for attackers.
    • Corporate and treasury banking — high-value users who benefit from dedicated hardware keys.
    • Retail customers — passwordless login to mobile and internet banking using device biometrics or passkeys.

    What to plan for

    FIDO2 is a strong foundation, but a successful rollout needs a few decisions up front:

    • Recovery. Customers lose phones and keys. Plan a secure re-enrolment process that does not reintroduce the weakest link, and consider registering more than one authenticator per user.
    • Transaction confirmation. FIDO2 proves who is logging in. For high-value payments, many banks add transaction signing so the customer confirms the actual amount and beneficiary on a trusted display.
    • Channel coverage. Decide how FIDO2 works alongside branch, call-centre and legacy channels during the transition.
    • Customer onboarding. Clear guidance at enrolment makes the difference between adoption and drop-off.

    In practice, banks usually combine FIDO2 with other authenticators matched to each customer segment — for example FIDO2 security keys with built-in fingerprint sensors alongside mobile soft tokens for customers who prefer to use their phone.

    Summary

    FIDO2 replaces passwords and one-time codes with device-held cryptographic keys bound to the bank's genuine website or app. That makes it resistant to phishing by design, faster for customers, and well aligned with the direction regulators are taking. For banks, the question is no longer whether to adopt phishing-resistant authentication, but which customers and channels to start with.

    Planning your authentication strategy?

    Talk to our team about the right mix of authentication and app security for your institution.

    Talk to an Expert