FIDO2 replaces passwords with cryptographically protected credentials. With an IDEX card, the Fido credentials and cryptographic keys are stored inside a secure element and never leave the card. Before credential information is passed to the requesting device the correct cryptographic keys must be used and a fingerprint match achieved.
Digital sign-in is an option chosen when cards are ordered, so not every IDEX card has it. You cannot tell by looking at the card – the app tells you when you set the PIN. See: Set your PIN.
Bound to a person, not just to a card
A standard security card works for whoever is holding it. The IDEX card requires a fingerprint match, so you can be confident that the credential in your logs was used by the person it was issued to – not by someone it was passed to.
One card instead of three
The card that opens your doors is also the FIDO2 authenticator and the photo ID badge. One item to issue, one to revoke, one for a user to lose – instead of a badge, a security key, and a password reset queue.
Phishing-resistant by design
The cards credentials are cryptographically and fingerprint protected. There is no password to steal, replay, or be talked into typing on a lookalike page.
Per-service keys
Each registration creates a separate key pair. Nothing is shared or correlated between services. The card holds up to 50 passkeys, so one card covers every service a user signs in to. See: Card models and configuration.
No batteries, no charging
The card is powered by the reader through NFC and works on both phones and computers.
See: Supported services, Register the card with a service and Set your PIN.