FIDO Alliance Sharpens Passkey Trust With New Metadata Service Rules

Pattern of various antique keys and keyholes arranged on a bright yellow background, representing the concept of security, access, or unlocking solutions.

The FIDO Alliance is tightening how relying parties evaluate passkeys and other FIDO authenticators, rolling out new versions of its Metadata Service (MDS) and a streamlined Convenience Metadata Service aimed at making it easier to separate trustworthy authenticators from outdated or non-compliant devices. The update is pitched as a way to raise assurance levels for passkey deployments without sacrificing user experience across mobile and desktop platforms.

FIDO’s Metadata Service acts as a central catalog of authenticator models, describing their capabilities, certification status, security properties, and lifecycle events. The latest MDS v3.1 and v3.1.1 releases introduce stricter publication requirements and enhanced checks around authenticator attestation and certification changes, giving relying parties better signals about whether specific devices still meet policy expectations. That additional context is increasingly important as passkeys spread across hardware form factors and mobile ecosystems, where vendors ship frequent firmware and platform updates.

To reduce integration friction, FIDO is also offering a new Convenience Metadata Service that presents a curated, easier-to-consume view of the same underlying information. The idea is to simplify adoption for service providers that do not need the full flexibility of the primary MDS, while still nudging them toward consistent enforcement of authenticator trust rules. For mobile-first services that depend on passkeys as a primary login mechanism, that convenience tier could help teams avoid implementation mistakes that create uneven security baselines across apps and operating systems.

For passkey programs, the change reinforces a key point: deploying FIDO is not just about turning on a new factor, but about continuously assessing the authenticators that users bring. Weak, misconfigured, or spoofed authenticators can undercut the promise of phishing-resistant authentication if relying parties treat all device models as equal. Aligning mobile and web deployments with the new MDS guidance, and baking metadata checks into risk engines and policy engines, will be critical steps for organizations that want to meet emerging phishing-resistant MFA expectations.

FIDO is encouraging vendors and relying parties to migrate to the new MDS versions and to review how they use metadata today, particularly in environments where mobile devices, platform authenticators, and cross-platform security keys all coexist. For identity and security teams, the updates offer an opportunity to revisit how authenticator trust decisions are made, documented, and audited across mobile and web channels.

Sources: FIDO Alliance, LinkedIn (FIDO Alliance), FIDO Alliance metadata

By the ID Tech Editorial Team