Identity
Multi-factor
An authenticator app or a passkey as a second step after email and social sign-ins.
Multi-factor adds a second step to a sign-in. Each application chooses which factors it offers.
Factors
| Factor | Second step |
|---|---|
| Authenticator app (TOTP) | The user enters the six-digit code from an authenticator app such as Google Authenticator or 1Password. |
| Passkey | The user confirms with a passkey on their device. |
When both are on, the user is asked for an authenticator code and can switch to a passkey instead.
Which sign-ins prompt for it
Email codes and social sign-ins (Apple, Google, X, Privage) go through the second factor when one is on.
Two sign-ins skip it:
- Passkey sign-in. A passkey already proves possession of the device and the user's presence, so asking again adds nothing.
- QR sign-in. The new device is approved from a device that is already signed in, which has already passed any second factor.
What your application sees
A session records which factor was used, so your application can require a stronger sign-in for sensitive actions.
{
"subject": "usr_demo_01",
"application": "example-app",
"sign_in_method": "email",
"factors": ["totp", "passkey"]
}