> For the complete documentation index, see [llms.txt](https://yubico.gitbook.io/yubikey5/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://yubico.gitbook.io/yubikey5/guides/understanding-pins/fido2.md).

# FIDO2

An explanation of the PIN associated to the FIDO2 interface.

## <mark style="color:red;">❊ FIDO2</mark>

FIDO2 is a technology / interface on your Yubikey, which stands for **Fast IDentity Online**. It is included on ALL models of Yubikey.

It is a standard which enables you to log into applications without using passwords on both desktop and mobile environments. Instead of passwords, FIDO authentication uses registered devices / security keys to validate you.

FIDO2 an extension of ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**FIDO U2F**](https://www.yubico.com/resources/glossary/fido-u2f/), and offers the same level of high-security based on public key cryptography. FIDO2 offers authentication options including single factor ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**(passwordless)**](https://www.yubico.com/resources/glossary/passwordless/), strong two factor (2FA), and multi-factor authentication (MFA).

FIDO2 key features include:

* <mark style="color:red;">**WebAuthn**</mark>: A standard set of web APIs to allow passwordless authentication in browsers
* <mark style="color:red;">**CTAP2**</mark>: Specification for the usage of physical keys and mobile authenticator apps to implement 2FA and passwordless authentication

You may be asking <mark style="color:red;">**"If FIDO2 is passwordless, why am I being asked for a password with services like Microsoft or Google"**</mark>.

A service might support devices like the Yubikey, however, may not support going completely passwordless. Instead, the website will ask you to enter your username/email and password, and then you will be prompted to insert your Yubikey device as a secondary factor of authentication (2FA). This means that you need your username/email + password + Yubikey device.

Not all services support Passwordless login yet unfortuantely.

At the time of writing this, Microsoft does support going passwordless. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**You can read about how to set this up here.**](https://support.microsoft.com/en-us/account-billing/how-to-go-passwordless-with-your-microsoft-account-674ce301-3574-4387-a93d-916751764c43)

### <mark style="color:blue;">FIDO2 PIN</mark>

The good news is that unlike GPG and PIV, with FIDO, you only have one PIN to remember. This is the PIN you will use when you attempt to sign into services like Google, Microsoft, Bitwarden, PayPal, etc.

There is no default FIDO PIN when you first get your Yubikey. It must be set up.

#### <mark style="color:yellow;">SET FIDO2 PIN</mark>

A FIDO2 PIN can be set on a YubiKey with Yubico’s program ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**YubiKey Manager**](https://www.yubico.com/support/download/yubikey-manager/).

When launching YubiKey Manager, open the program with Administrative Permissions by right-clicking on the program and selecting <mark style="color:red;">**Run as administrator**</mark>

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FiTi8rbiuuY0pN5Mxmwgn%2Fyubikey_fido.png?alt=media&amp;token=be2e27c3-ea4d-428b-9c4b-3af25ba02c3d" alt=""><figcaption></figcaption></figure>

Once loaded, navigate to **Applications** -> **FIDO2** and clicking **Set PIN or** ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2F4otUfsUznMo3WaJOoXO4%2Ffido_btn_changepin.png?alt=media\&token=078fa70b-e7b8-40ad-ad8d-9ff35f4783e3)

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2F2uIqf7JpNa1rJrYelmAU%2Fanim_fido.gif?alt=media&amp;token=2f475380-f656-42c8-baf1-ddcbc8db740c" alt=""><figcaption></figcaption></figure>

You also have a button to **Reset** your FIDO2 PIN by selecting: ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2F6WnqMwq1IVgXmHcgiVq6%2Ffido_btn_reset.png?alt=media\&token=2b333584-131d-481a-942b-7be16065c4fe)
