---
url: 'https://www.corbado.com/faq/what-is-a-fido-soft-token'
title: 'What is a FIDO soft token?'
description: 'A FIDO soft token is a software-based FIDO authenticator built into a company''s own mobile app. Learn how it differs from a synced passkey and a hardware security key.'
lang: 'en'
keywords: 'fido soft token, fido softtoken, what is a fido soft token, fido soft token vs passkey, fido software token'
---

# What is a FIDO soft token?

## What is a FIDO soft token?

A **FIDO soft token**, also called a software token or software authenticator, is a
FIDO-certified authenticator that runs as software inside a mobile app instead of on a
dedicated hardware device. Companies license it from a vendor as an SDK and embed it in
their own app. The user never sees the vendor's name. The app asks for a fingerprint, face
scan or PIN. The private key that signs the login challenge stays on that one phone.

The term comes up mostly in banking. Asian banks were among the earliest to ship it.
Korea's Kookmin Bank put a FIDO authenticator into its KBStar banking app in November 2016.
At that time Korea had 65 million mobile banking subscribers, most of them still on
passwords. By October 2018 the authenticator handled 16 million transactions a month and more
than 260 million in total. About 3.5 million customers used it, according to a
[FIDO Alliance case study](https://fidoalliance.org/kookmin-bank-leverages-crosscert-fido-to-provide-easy-biometric-authentication-to-its-customers/).
Malaysia's Maybank introduced its in-app Secure2u token in
[April 2017](https://www.maybank.com/en/news/2022/09/28.page).

> "To date, Korea is one of the most advanced countries where FIDO has been successfully
> deployed for various financial services nationwide." Dr. Jaejung Kim, KICA, in a
> [FIDO Alliance white paper](https://fidoalliance.org/wp-content/uploads/FIDO-Deployment-Case-Study-K-FIDO_170905.pdf)
> (2017)

Kookmin and Maybank both launched years before Apple, Google and Microsoft
[committed to passkeys](https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/)
in May 2022. That history causes a specific confusion: people hear "software" and assume it
behaves like a synced [passkey](https://www.corbado.com/glossary/passkey), moving between a user's phone and
laptop. It does not. The credential is
[device-bound](https://www.corbado.com/blog/device-bound-synced-passkeys), which is the same category as a hardware
security key, not the same category as an iCloud Keychain or Google Password Manager
passkey.

---

## How is a FIDO soft token different from a synced passkey?

A soft token and a synced passkey both use public key cryptography and both unlock with
a fingerprint, face scan or PIN. The difference is portability. The token lives in one app
on one phone and has to be enrolled again on a new device. A synced passkey is copied across
a user's devices by Apple, Google or a password manager.

|                            | FIDO soft token                       | Synced passkey                                                                     |
| -------------------------- | -------------------------------------- | ------------------------------------------------------------------------------------ |
| **Where it runs**          | A single app, via a vendor SDK        | The [platform authenticator](https://www.corbado.com/glossary/platform-authenticator), built into the OS  |
| **Private key lives**      | In that one phone's keystore          | Synced across a user's devices by Apple, Google or a password manager              |
| **Moves to a new phone?**  | No, the user enrolls again            | Yes, through the platform's sync account                                            |
| **Typical use case**       | A single regulated app, often banking | Any website or app that supports [WebAuthn](https://www.corbado.com/glossary/webauthn)                    |

Both are FIDO credentials in the sense that neither ever sends the private key anywhere and
both resist [phishing](https://www.corbado.com/glossary/phishing), because each signature is bound to the service
the credential was created for. A device-bound credential, whether it sits in an app or on a
hardware security key, does not leave its device.

See [are passkeys device specific](https://www.corbado.com/faq/are-passkeys-device-specific) for the same
distinction on the passkey side, and
[why synced passkeys were introduced](https://www.corbado.com/faq/why-synced-passkeys-benefits) for the case for
syncing in the first place.

## How is a FIDO soft token different from a hardware security key?

A software authenticator and a hardware security key solve the same problem in different
packaging. A hardware key such as a YubiKey stores the credential on a separate device that
the user plugs in over USB or taps over NFC. The app-based version stores the equivalent
credential inside the phone the user already carries, so there is no hardware to buy, ship
or replace.

On the phone, the key usually sits in a hardware-backed keystore such as the iPhone
[Secure Enclave](https://www.corbado.com/glossary/secure-enclave) or the Android Keystore, and the app unlocks it
after a local biometric or PIN check. Some products protect the key with software alone:
Giesecke+Devrient roots key storage for its authenticator in an
[application security framework](https://www.gi-de.com/en/digital-security/identity-technology/enterprise-security/software-based-authentication)
instead of dedicated hardware. The trade-off is lock-in, because the credential is tied to
whichever vendor SDK issued it rather than to the platform's own passkey API.

## Which vendors build FIDO soft tokens?

As of September 2026, vendors with FIDO-certified authenticator SDKs include Daon, OneSpan,
RaonSecure, Giesecke+Devrient, Aware and Veridium. Each sells an SDK that a bank or another
regulated company embeds in its own mobile app. Nok Nok Labs, one of the earliest vendors in
this space, has been part of OneSpan since June 2025.

| Vendor            | Product                                      | Note                                                            |
| ----------------- | -------------------------------------------- | --------------------------------------------------------------- |
| Daon              | IdentityX                                    | FIDO UAF, among the first FIDO Certified products in June 2015  |
| OneSpan           | FIDO UAF Client SDK, Nok Nok Authenticator SDK | FIDO UAF, acquired Nok Nok Labs in June 2025                 |
| RaonSecure        | TouchEn OnePass                              | FIDO UAF, used by Korean banks and all three Korean carriers    |
| Giesecke+Devrient | StarSign FIDO SW Authenticator               | FIDO UAF, software-only authenticator for Android and iOS apps  |
| Aware             | Face and Face+Voice Authenticators           | FIDO UAF 1.1, biometric login inside banking apps               |
| Veridium          | Mobile SDK for iOS and Android               | Listed as FIDO Certified Authenticator since November 2021      |

Many of these SDKs predate browser support for passkeys. The
[FIDO UAF protocol](https://fidoalliance.org/specs/fido-uaf-v1.0-ps-20141208/fido-uaf-protocol-v1.0-ps-20141208.html)
was published in December 2014, while WebAuthn only became a
[W3C standard](https://www.w3.org/press-releases/2019/webauthn/) in March 2019. That is why
many deployments still run on UAF through the vendor's own client library. Newer
deployments can build on the phone's native [FIDO2](https://www.corbado.com/glossary/fido2) APIs instead, which
narrows the practical gap between a vendor SDK and a device-bound passkey issued by
the OS itself.

## How Corbado can help

A soft token, a device-bound passkey and a synced passkey all look similar from the outside:
the user unlocks something with a fingerprint. Telling them apart in production traffic is
harder. [Corbado Observe](https://www.corbado.com/observe) is the
[authentication observability](https://www.corbado.com/blog/authentication-observability) layer that reads the
[AAGUID](https://www.corbado.com/glossary/aaguid) off every login, so a rollout that mixes a legacy soft token with
newer passkeys shows up as two distinct credential types instead of one blended number.

[Video: Authenticator inventory](https://www.corbado.com/videos/features/authenticator-inventory.mp4) ([See Authenticator Inventory in Corbado Observe](https://www.corbado.com/observe/authenticator-inventory))

- **See what is actually authenticating.** The Authenticator Inventory separates a vendor
  soft token from a [hardware security key](https://www.corbado.com/blog/best-fido2-hardware-security-keys) or a
  platform passkey, so a migration off a vendor SDK has a real baseline to measure against.
- **Catch enrollment failures per credential type.** [Passkey errors](https://www.corbado.com/observe/passkey-errors)
  split cancellations from real failures, which matters when a soft token migration means
  every user has to enroll again.

For teams moving off a vendor soft token toward passkeys issued by the platform itself,
[Corbado Connect](https://www.corbado.com/connect) adds managed passkeys next to the existing setup, so the
[migration](https://www.corbado.com/blog/native-app-passkeys) can run in waves instead of a single cutover.

---
