Authentication
MFA and passkeys
Authenticator-app codes, recovery codes and passkeys.
Authenticator-app MFA#
Users enroll by scanning a QR code on the hosted page and confirming a six-digit code (TOTP). At every later sign-in they are asked for a code after the first factor. Enrollment is sent as an mfa.factor_enrolled webhook event.
Off, optional or required#
Set per environment. Optional lets users enroll themselves. Required asks every user to enroll at their next sign-in, before a session is issued.
Passkeys#
With passkeys turned on for the environment, users can register one on the hosted page after signing in, then sign in with it (WebAuthn). The credential is bound to your hosted domain.
With the embedded form#
The embedded SignIn handles the TOTP step. It sends users who still need to enroll, or who want a passkey, to the hosted page.