HCE Entitlement eligibility - Device-to-Device use case for FIDO/passkey authentication

Hello,

We operate PasskeyGuard, an iOS passkey/FIDO2 authentication app, and are evaluating adding NFC support. We'd like to confirm eligibility before starting development or submitting a formal entitlement request.

Intended flow: Our iPhone app acts as the host (Host Card Emulation). Another device reads the iPhone over NFC to perform a FIDO2/WebAuthn authentication (the phone acts as a security-key-style authenticator, transmitting authentication data over NFC to the reading device).

Based on the HCE support article, the closest matching category appears to be "Device-to-Device transactions." Our questions:

  1. Is a FIDO2/passkey authentication use case eligible under the Device-to-Device HCE entitlement, or does it fall outside the currently supported use cases?
  2. If eligible: are we permitted to register a custom applet AID (specifically the FIDO2 NFC AID A0000006472F0001) via CardSession, or is the set of allowed AIDs restricted per use case?
  3. Are there requirements beyond an EEA-established Organization account and the general "legal right / regulatory permissions" attestation that apply specifically to an authentication use case?

We want to avoid investing development effort against an entitlement that may not be granted for this use case. Any guidance on eligibility and next steps would be greatly appreciated.

Thank you, Alexander Friedl

There is no point in speculating on the forums about whether you would be getting the entitlement, and whether your use case, etc. is acceptable, when you can just easily directly ask the entitlement team, who would be making the decisions, by filling out the request form.

Whatever is said here will eventually has to be accepted by them, on a case by case basis.

HCE Entitlement eligibility - Device-to-Device use case for FIDO/passkey authentication
 
 
Q