Passkey users
Users with Passkeys (biometric authentication) are configured. Provides a smooth login process where supported.
Options
[Non-Trusted Device]
Non-Trusted Device
Log in with username/password.
Prompted with a biometric challenge (pin code, face recognition, fingerprint)

Successful biometric unlocks the account, with a trust option available.

[Trusted Device]
Trusted Device
Log in again from a trusted device
Passkey challenge skipped.
The user is presented with an option to extend device trust, followed by direct access to the dashboard.
[Expired Trust]
Expired Trust
After trust expiry, the user must pass the biometric challenge again.
Trust option re-shown post verification.
[Unsupported Environment]
Unsupported Environment
Some browsers/devices may not support passkey.
In those cases, the user is redirected to fallback MFA (TOTP or OTP).