Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Drupal 10.6.17 Update released for Drupal core (10.6.17)! Release: Drupal 11.3.17 Update released for Drupal core (11.3.17)! Release: Drupal 11.4.7 Update released for Drupal core (11.4.7)! Release: CKEditor 5 Plugin Pack 1.5.5 Minor update available for module ckeditor5_plugin_pack (1.5.5). Release: CKEditor 5 Premium Features 1.8.4 Minor update available for module ckeditor5_premium_features (1.8.4). Release: AI (Artificial Intelligence) 1.3.14 Minor update available for module ai (1.3.14). Release: AI (Artificial Intelligence) 1.4.9 Minor update available for module ai (1.4.9). Release: Copyright Footer 3.3.0 Minor update available for module copyright_footer (3.3.0). Usage Milestone: Easy Email Module easy_email crossed 10,000 active installs. Module Revived: Commerce Stripe 2.2.2 Module commerce_stripe updated after 6 months of inactivity (2.2.2).

Fido2auth

No security coverage Drupal 11 · not 10
View on drupal.org

This module allows users to log in to your Drupal site without a password using FIDO2/WebAuthn. Users can register devices like security keys, fingerprint scanners, or their phone to authenticate, enhancing security and improving the user experience.

FIDO2 Auth brings passwordless login to Drupal using the WebAuthn standard.
Users can authenticate with fingerprint, face scan, hardware security keys, or
their phone — eliminating weak or reused passwords from your site.

How it works

Instead of typing a password, users register one or more FIDO2 keys (security
keys, device biometrics, or cross-device passkeys). On subsequent visits they
enter only their username and complete a browser prompt — tap a YubiKey, scan
a fingerprint, or unlock their phone.

Features

- True passwordless login — username + authenticator, no password fallback
required
- Multiple authenticator types — USB/NFC/BLE security keys, platform
biometrics (Windows Hello, Touch ID, Android), and hybrid cross-device
passkeys
- User-managed keys — users register and revoke their own keys from their
profile page
- Configurable security policy — challenge timeout, resident key requirements,
user verification level (PIN/biometric), allowed transports, and max keys per
user
- Flood protection — rate-limited challenge and login endpoints per IP
- Anti-enumeration — unknown usernames receive a fake challenge so attackers
cannot probe for valid accounts
- Plays well with others — works alongside the standard password login form;
users can keep both or rely solely on passkeys

Requirements

- HTTPS (required by browsers for WebAuthn; localhost allowed during
development)
- PHP 8.1+ with gmp or bcmath
- The lbuchs/webauthn library (installed via Composer)

Depends on

Dependencies of the latest stable release

  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
May 2026
Latest release
4 months ago
Releases (12 mo)
4 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.3 Stable 11 May 6, 2026
1.0.1 Stable 11 May 6, 2026
1.0.0 Stable 11 May 5, 2026
1.0.x-dev Dev 11 May 4, 2026