Drupal is a registered trademark of Dries Buytaert
Release: Paragraphs 8.x-1.22 Minor update available for module paragraphs (8.x-1.22). Release: Menu Item Extras 3.1.2 Minor update available for module menu_item_extras (3.1.2). Release: Drupal Admin App 2.3.5 Minor update available for module drupal_admin_app (2.3.5). Release: REST OAI-PMH 2.3.3 Minor update available for module rest_oai_pmh (2.3.3). Release: RulesFinder 2.0.15 Minor update available for distribution rules_finder (2.0.15). Release: REMP Paywall 2.0.1 Minor update available for module remp (2.0.1). Module Revived: oEmbed Providers 2.2.4 Module oembed_providers updated after 7 months of inactivity (2.2.4). Release: FlowDrop 2.0.0-alpha15 New alpha version released for module flowdrop (2.0.0-alpha15). Release: Vartheme Bs5 5.0.0-rc1 First release candidate for theme vartheme_bs5 (5.0.0-rc1). Security Coverage: REMP Paywall Module remp now has official Drupal security advisory coverage.

Fido2auth

No security coverage
View on drupal.org

This module allows users to log in to your Drupal site without a password using FIDO2/WebAuthn. Users can register devices like security keys, fingerprint scanners, or their phone to authenticate, enhancing security and improving the user experience.

FIDO2 Auth brings passwordless login to Drupal using the WebAuthn standard.
Users can authenticate with fingerprint, face scan, hardware security keys, or
their phone — eliminating weak or reused passwords from your site.

How it works

Instead of typing a password, users register one or more FIDO2 keys (security
keys, device biometrics, or cross-device passkeys). On subsequent visits they
enter only their username and complete a browser prompt — tap a YubiKey, scan
a fingerprint, or unlock their phone.

Features

- True passwordless login — username + authenticator, no password fallback
required
- Multiple authenticator types — USB/NFC/BLE security keys, platform
biometrics (Windows Hello, Touch ID, Android), and hybrid cross-device
passkeys
- User-managed keys — users register and revoke their own keys from their
profile page
- Configurable security policy — challenge timeout, resident key requirements,
user verification level (PIN/biometric), allowed transports, and max keys per
user
- Flood protection — rate-limited challenge and login endpoints per IP
- Anti-enumeration — unknown usernames receive a fake challenge so attackers
cannot probe for valid accounts
- Plays well with others — works alongside the standard password login form;
users can keep both or rely solely on passkeys

Requirements

- HTTPS (required by browsers for WebAuthn; localhost allowed during
development)
- PHP 8.1+ with gmp or bcmath
- The lbuchs/webauthn library (installed via Composer)

Activity

Tracked releases
4
Tracked since
May 2026
Latest release
2 months ago
Releases (12 mo)
4 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Release date
1.0.3 Stable May 6, 2026
1.0.1 Stable May 6, 2026
1.0.0 Stable May 5, 2026
1.0.x-dev Dev May 4, 2026