pr0dDOCS
Identity

Multi-factor

An authenticator app or a passkey as a second step after email and social sign-ins.

Multi-factor adds a second step to a sign-in. Each application chooses which factors it offers.

Factors

FactorSecond step
Authenticator app (TOTP)The user enters the six-digit code from an authenticator app such as Google Authenticator or 1Password.
PasskeyThe user confirms with a passkey on their device.

When both are on, the user is asked for an authenticator code and can switch to a passkey instead.

Which sign-ins prompt for it

Email codes and social sign-ins (Apple, Google, X, Privage) go through the second factor when one is on.

Two sign-ins skip it:

  • Passkey sign-in. A passkey already proves possession of the device and the user's presence, so asking again adds nothing.
  • QR sign-in. The new device is approved from a device that is already signed in, which has already passed any second factor.

What your application sees

A session records which factor was used, so your application can require a stronger sign-in for sensitive actions.

{
  "subject": "usr_demo_01",
  "application": "example-app",
  "sign_in_method": "email",
  "factors": ["totp", "passkey"]
}

On this page