MFA-Passkeys (FIDO2 / WebAuthn)
Last updated
Last updated
This section explains how to use Passkeys (FIDO2 / WebAuthn) as a Multi-Factor Authentication (MFA) method, including:
What passkeys are and how they work
How to set up a passkey
How passkey verification works during sign-in
Passkeys are a passwordless, phishing-resistant authentication method that uses your device’s built-in security (biometrics or screen lock).
If you want the highest level of account security with the simplest user experience, passkeys are the recommended option.
Passkeys allow you to:
Sign in using biometrics (Face ID, Touch ID, Windows Hello)
Or your device PIN / screen lock
Avoid typing one-time codes or passwords during verification
Passkeys are supported on:
Modern browsers (Chrome, Safari, Edge, Firefox)
iOS, Android, macOS, Windows devices
Passkeys provide strong, phishing-resistant authentication by:
This significantly reduces risks from:
Before setting up a passkey, make sure that:
⚠️ Email verification is automatically enabled when MFA is turned on. Passkeys are added as an additional verification method.
🔐 Your private key is securely stored on your device and never shared.
Once verified:
When signing in with passkey enabled:
Device lost or replaced?
Passkey not available?
Eliminating shared secrets (no codes to steal)
Binding authentication to a specific device
Leveraging FIDO2 / WebAuthn standards
Phishing attacks
Credential reuse
Man-in-the-middle attacks
Your account is created and signed in
Multi-Factor Authentication (MFA) is enabled
Your device supports:
Biometrics (Face ID, Touch ID, fingerprint), or
Secure screen lock (PIN / pattern)
You are using a supported browser

Go to Account → Security
Turn on Multi-Factor Authentication
In Security → Multi-Factor Authentication
Select Passkey
Click Set up passkey
Click Create passkey
Click Continue
Follow the on-screen instructions provided by your device:
Face ID / Touch ID
Device PIN or screen lock
Your passkey is registered
MFA using passkey is now active
Enter your email and password
Passkey is selected as the default verification method
Click button Continue
Verify your identity using a registered passkey.
✅ Sign-in completes automatically after successful verification.
Passkeys are phishing-resistant
No verification codes are generated or transmitted
Private keys never leave your device
Each passkey is bound to a specific device
You can remove a passkey from Security settings at any time
Use Email MFA or Authenticator App (if enabled)
Register a new passkey on your new device
Ensure your browser and OS are up to date
Make sure device lock or biometrics are enabled
Item
Description
MFA method
Passkeys (FIDO2 / WebAuthn)
Verification type
Biometrics / Device lock
Used during
Sign-in after password
Internet required
No (after initial setup)
Security level
Very high
Best for
Passwordless-like, high-security access





