{
  "node_id": "w3c-webauthn-level-3-2024-passkeys-fido2",
  "title": "W3C Web Authentication (WebAuthn) Level 3 - Passkeys and FIDO2 Phishing-Resistant Authentication",
  "domain": "Workflow Automation",
  "version": "1.0.0",
  "last_updated": "2026-05-09",
  "bluf": "W3C Web Authentication (WebAuthn) Level 3 (W3C Recommendation, 2024, building on WebAuthn Level 2 - March 2021) in conjunction with FIDO Alliance FIDO2 Client to Authenticator Protocol (CTAP 2.2) defines the standard for phishing-resistant, hardware-backed authentication using public key cryptography. WebAuthn enables passkeys - discoverable credentials stored in authenticators (device biometrics, hardware security keys) that replace passwords for website and application authentication. NIST SP 800-63-3 classifies FIDO2/WebAuthn at IAL2/AAL2+ (for FIDO2 with hardware authenticators). Organizations implementing WebAuthn for enterprise workflow authentication eliminate credential phishing risk, reduce password management costs, and achieve MFA compliance for frameworks including PCI DSS 4.0, NIS2 Directive, and NIST Cybersecurity Framework. AI agents may use WebAuthn-derived credentials for service authentication in zero-trust workflow environments.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "eu_ai_act",
      "industry_mapping",
      "iso_standard",
      "related_frameworks"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "ietf-oauth-2-1-authorization-framework",
    "w3c-did-core-1-0-decentralized-identifiers"
  ],
  "primary_citations_count": 7
}