Two separate jobs
FIDO2 authenticates a device to an online service using public-key cryptography. The biometric verifies the user locally before the device uses its private key. The fingerprint is not sent to the website.
Why it resists phishing
Credentials are bound to the legitimate service origin, so a look-alike site cannot simply reuse them. This addresses a central weakness of passwords and one-time codes.
Device-bound versus synced
A card is typically a device-bound authenticator: its private keys remain on that hardware. Synced passkeys trade some hardware assurance for convenience across devices. Organizations can choose based on threat model and recovery needs.
Certification and assurance
FIDO certification helps establish protocol conformance, but it is not a complete security verdict. Buyers should also examine authenticator assurance, secure hardware, biometric performance and operational controls.
Deployment checklist
Confirm operating-system and browser support, NFC or reader needs, identity-provider policy, attestation requirements, spare authenticators, recovery, lifecycle management and accessibility alternatives.