CTAP 2.3 draft notes: what applies to a phone passkey provider, and what does not
SHORT ANSWER
Does the FIDO CTAP 2.3 draft apply to a passkey app on an Android phone?
Mostly not directly. CTAP defines how a client talks to a roaming authenticator over USB, NFC, Bluetooth or the hybrid transport. An Android passkey provider is reached through Credential Manager and WebAuthn instead, so WebAuthn is the specification it must follow. CTAP 2.3 is also still a review draft.
Key takeaways
- CTAP 2.3 is a review draft dated 23 October 2025, and its own status text says it is not a basis for implementations because it may change.
- CTAP is about roaming authenticators. A provider behind Android's Credential Manager speaks WebAuthn, not CTAP.
- The standard cross-device sign-in, the hybrid transport, appears in the draft and is run by Android for providers like ours.
- HostSpica Passkey follows WebAuthn and makes no CTAP conformance claim. It is not FIDO certified.
What CTAP is
The Client to Authenticator Protocol (CTAP) is the half of FIDO2 that describes how a browser or operating system talks to an authenticator that is a separate device, such as a USB security key. WebAuthn, from the W3C, is the other half: how a website asks for a credential. When you tap a security key on a laptop, CTAP carries the request over USB, NFC or Bluetooth Low Energy.
Where the draft stands
The CTAP 2.3 draft we read is a review draft published on 23 October 2025. The previous Proposed Standard is CTAP 2.2 from July 2025. A review draft is circulated for feedback and can change, and the draft says as much about itself, so building to it as if it were final would be a mistake. Our summary here was prepared from the published draft and can contain mistakes, so read the source yourself for anything that matters to you.
What is in it, as we read it
- The scope statement describes authenticators used from a client platform, with a roaming authenticator, as the target.
- Transports are defined separately: USB HID, NFC, Bluetooth Low Energy, and hybrid transports, which cover the QR-initiated flow in which a phone acts as the authenticator for another device.
- A set of commands (make a credential, get an assertion, report the authenticator's capabilities, and PIN or user-verification handling) forms the core, with optional ones such as credential management and large blobs.
- Extensions such as credential protection, a per-credential blob and the
hmac-secretsecret derivation are specified, and some are widely implemented. - Enterprise attestation and PIN policy features are described for managed settings.
What applies to an Android passkey provider
| Topic | For a provider behind Credential Manager |
|---|---|
| Command set and CBOR framing | Not ours: Android's platform speaks it, or WebAuthn JSON replaces it. We receive WebAuthn requests and return WebAuthn responses. |
| Transports (USB, NFC, BLE) | Not ours. A phone provider is not a security key. |
| Hybrid transport | Run by Android when you scan a computer's QR code with the camera. It makes our provider available; the system, not our app, runs it, and it may use the internet and Bluetooth. |
| Authenticator data, flags, attestation, COSE keys | Ours, and defined by WebAuthn. See our WebAuthn checklist. |
| Extensions | Only the WebAuthn extensions we implement. Today that is credProps. |
What we do and do not claim
Why we dropped our own cross-device protocol
Before we understood how Android handles the hybrid flow we built our own Bluetooth pairing protocol. It worked only on sites that used our script, so we removed it. The story is in why we dropped our custom Bluetooth passkey protocol.
Frequently asked questions
Why read a draft at all?
Because standards move, and knowing where CTAP is heading helps us judge what Android's platform will ask of providers over time.
Will you implement CTAP?
Not as things stand. There is no need for it behind Credential Manager. We will revisit if we ever build a roaming mode.
Is HostSpica Passkey FIDO certified?
No. Certification is a separate process run by the FIDO Alliance, and we have not undertaken it.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED