Drupal is a registered trademark of Dries Buytaert
drupal 11.3.8 Update released for Drupal core (11.3.8)! drupal 11.3.7 Update released for Drupal core (11.3.7)! drupal 11.2.11 Update released for Drupal core (11.2.11)! drupal 10.6.7 Update released for Drupal core (10.6.7)! drupal 10.5.9 Update released for Drupal core (10.5.9)! cms 2.1.1 Update released for Drupal core (2.1.1)! drupal 11.3.6 Update released for Drupal core (11.3.6)! drupal 10.6.6 Update released for Drupal core (10.6.6)! cms 2.1.0 Update released for Drupal core (2.1.0)! linkit 7.0.14 Minor update available for module linkit (7.0.14). masquerade 8.x-2.2 Minor update available for module masquerade (8.x-2.2). video_embed_field 3.1.0 Minor update available for module video_embed_field (3.1.0). bootstrap 8.x-3.40 Minor update available for theme bootstrap (8.x-3.40). menu_link_attributes 8.x-1.7 Minor update available for module menu_link_attributes (8.x-1.7). webform 6.3.0-beta9 New beta version released for module webform (6.3.0-beta9). tagify 1.2.51 Minor update available for module tagify (1.2.51). symfony_mailer 2.0.0 Major update available for module symfony_mailer (2.0.0). editoria11y 3.0.1 Minor update available for module editoria11y (3.0.1). geofield_map 11.1.9 Minor update available for module geofield_map (11.1.9). domain 3.0.0 Major update available for module domain (3.0.0).

fido2auth

No security coverage
View on drupal.org

FIDO2 Auth brings passwordless login to Drupal using the WebAuthn standard.
Users can authenticate with fingerprint, face scan, hardware security keys, or
their phone — eliminating weak or reused passwords from your site.

How it works

Instead of typing a password, users register one or more FIDO2 keys (security
keys, device biometrics, or cross-device passkeys). On subsequent visits they
enter only their username and complete a browser prompt — tap a YubiKey, scan
a fingerprint, or unlock their phone.

Features

- True passwordless login — username + authenticator, no password fallback
required
- Multiple authenticator types — USB/NFC/BLE security keys, platform
biometrics (Windows Hello, Touch ID, Android), and hybrid cross-device
passkeys
- User-managed keys — users register and revoke their own keys from their
profile page
- Configurable security policy — challenge timeout, resident key requirements,
user verification level (PIN/biometric), allowed transports, and max keys per
user
- Flood protection — rate-limited challenge and login endpoints per IP
- Anti-enumeration — unknown usernames receive a fake challenge so attackers
cannot probe for valid accounts
- Plays well with others — works alongside the standard password login form;
users can keep both or rely solely on passkeys

Requirements

- HTTPS (required by browsers for WebAuthn; localhost allowed during
development)
- PHP 8.1+ with gmp or bcmath
- The lbuchs/webauthn library (installed via Composer)

Activity

Total releases
1
First release
May 2026
Latest release
15 hours ago
Release cadence
Stability
0% stable

Releases

Version Type Release date
1.0.x-dev Dev May 4, 2026