A FIDO soft token, also called a software token or software authenticator, is a FIDO-certified authenticator that runs as software inside a mobile app instead of on a dedicated hardware device. Companies license it from a vendor as an SDK and embed it in their own app. The user never sees the vendor's name. The app asks for a fingerprint, face scan or PIN. The private key that signs the login challenge stays on that one phone.
The term comes up mostly in banking. Asian banks were among the earliest to ship it. Korea's Kookmin Bank put a FIDO authenticator into its KBStar banking app in November 2016. At that time Korea had 65 million mobile banking subscribers, most of them still on passwords. By October 2018 the authenticator handled 16 million transactions a month and more than 260 million in total. About 3.5 million customers used it, according to a FIDO Alliance case study. Malaysia's Maybank introduced its in-app Secure2u token in April 2017.
"To date, Korea is one of the most advanced countries where FIDO has been successfully deployed for various financial services nationwide." Dr. Jaejung Kim, KICA, in a FIDO Alliance white paper (2017)
Kookmin and Maybank both launched years before Apple, Google and Microsoft committed to passkeys in May 2022. That history causes a specific confusion: people hear "software" and assume it behaves like a synced passkey, moving between a user's phone and laptop. It does not. The credential is device-bound, which is the same category as a hardware security key, not the same category as an iCloud Keychain or Google Password Manager passkey.
A soft token and a synced passkey both use public key cryptography and both unlock with a fingerprint, face scan or PIN. The difference is portability. The token lives in one app on one phone and has to be enrolled again on a new device. A synced passkey is copied across a user's devices by Apple, Google or a password manager.
| FIDO soft token | Synced passkey | |
|---|---|---|
| Where it runs | A single app, via a vendor SDK | The platform authenticator, built into the OS |
| Private key lives | In that one phone's keystore | Synced across a user's devices by Apple, Google or a password manager |
| Moves to a new phone? | No, the user enrolls again | Yes, through the platform's sync account |
| Typical use case | A single regulated app, often banking | Any website or app that supports WebAuthn |
Both are FIDO credentials in the sense that neither ever sends the private key anywhere and both resist phishing, because each signature is bound to the service the credential was created for. A device-bound credential, whether it sits in an app or on a hardware security key, does not leave its device.
See are passkeys device specific for the same distinction on the passkey side, and why synced passkeys were introduced for the case for syncing in the first place.
A software authenticator and a hardware security key solve the same problem in different packaging. A hardware key such as a YubiKey stores the credential on a separate device that the user plugs in over USB or taps over NFC. The app-based version stores the equivalent credential inside the phone the user already carries, so there is no hardware to buy, ship or replace.
On the phone, the key usually sits in a hardware-backed keystore such as the iPhone Secure Enclave or the Android Keystore, and the app unlocks it after a local biometric or PIN check. Some products protect the key with software alone: Giesecke+Devrient roots key storage for its authenticator in an application security framework instead of dedicated hardware. The trade-off is lock-in, because the credential is tied to whichever vendor SDK issued it rather than to the platform's own passkey API.
As of September 2026, vendors with FIDO-certified authenticator SDKs include Daon, OneSpan, RaonSecure, Giesecke+Devrient, Aware and Veridium. Each sells an SDK that a bank or another regulated company embeds in its own mobile app. Nok Nok Labs, one of the earliest vendors in this space, has been part of OneSpan since June 2025.
| Vendor | Product | Note |
|---|---|---|
| Daon | IdentityX | FIDO UAF, among the first FIDO Certified products in June 2015 |
| OneSpan | FIDO UAF Client SDK, Nok Nok Authenticator SDK | FIDO UAF, acquired Nok Nok Labs in June 2025 |
| RaonSecure | TouchEn OnePass | FIDO UAF, used by Korean banks and all three Korean carriers |
| Giesecke+Devrient | StarSign FIDO SW Authenticator | FIDO UAF, software-only authenticator for Android and iOS apps |
| Aware | Face and Face+Voice Authenticators | FIDO UAF 1.1, biometric login inside banking apps |
| Veridium | Mobile SDK for iOS and Android | Listed as FIDO Certified Authenticator since November 2021 |
Many of these SDKs predate browser support for passkeys. The FIDO UAF protocol was published in December 2014, while WebAuthn only became a W3C standard in March 2019. That is why many deployments still run on UAF through the vendor's own client library. Newer deployments can build on the phone's native FIDO2 APIs instead, which narrows the practical gap between a vendor SDK and a device-bound passkey issued by the OS itself.
A soft token, a device-bound passkey and a synced passkey all look similar from the outside: the user unlocks something with a fingerprint. Telling them apart in production traffic is harder. Corbado Observe is the authentication observability layer that reads the AAGUID off every login, so a rollout that mixes a legacy soft token with newer passkeys shows up as two distinct credential types instead of one blended number.
See Authenticator Inventory in Corbado Observe →For teams moving off a vendor soft token toward passkeys issued by the platform itself, Corbado Connect adds managed passkeys next to the existing setup, so the migration can run in waves instead of a single cutover.
Corbado is the Passkey Intelligence Platform for large-scale CIAM teams running consumer authentication. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert →
Next Step: Ready to implement passkeys at your bank? Our +90-page Banking Passkeys Report is available.
Get the Report
Table of Contents
Related Articles