Skip to main content

Attestation

At registration, an authenticator can include a signed statement identifying what it is, so a service can verify that a credential was created on approved hardware rather than in a software vault. Most consumer services ignore it; enterprise deployments use it to enforce hardware policies. See FIDO2 Integration Guide.

See Also