FIDO2 compatible WebAuthn Authenticator are built into Operating System and Mobile Devices. Thus, you can use your mobile phone as a WebAuthn Authenticator. The phone will use security features available on the device to protect your credentials. This could be a PIN to unlock the phone, or data from the fingerprint reader. Most modern Browsers are now compatible with WebAuthN and offer built-in WebAuthn Authenticators that can communicate with the Operating System to authorize a user.
An important feature of an WebAuthn Authenticator is that it connects with the client without using the Internet using the Client To Authenticator Protocol. You can use your Mobile Device as an WebAuthn Authenticator to log in to a website opened on your laptop, but the phone has to connect to your computer via Bluetooth Low Energy. This prevents any Man-In-The-Middle attacks on the data exchanged between the WebAuthn Client and WebAuthn Authenticator. Thanks to this, the WebAuthn Client can be sure it is really communicates with the WebAuthn Authenticator and that the data has not been tampered with.
WebAuthn Authenticators may be one or the other:
WebAuthn Authenticators may utilize: