FeatureEvery plan

Passkeys and two-factor

Sign in with a passkey or add an authenticator app with one-time recovery codes. The second factor is enforced on the server, on every plan.

By Updated

Add a passkey from Settings, Security and your fingerprint, face, or device PIN becomes the login. Nothing to remember, nothing to phish.

Half a minute, and it replaces typing a code every time.

  1. Open Settings, Security.

    Passkeys and two-factor both live here. Everything on this page runs in the browser, because WebAuthn cannot work any other way.

    Open security settings
  2. Press Add a passkey and follow your device.

    Your device asks for the fingerprint, face or PIN it already uses. None of that reaches ToDidIt: what is stored is a public key, and the biometric never leaves the device.

  3. Keep a second way in.

    A passkey lives on one device unless your password manager syncs it. Add a second, or keep the email code available, so a lost phone is an inconvenience rather than a lockout.

Enroll any TOTP app. When you do, you also get one-time recovery codes for the day you lose your phone. Save them somewhere that is not your phone.

A session that has not cleared its second factor is stopped before it reaches your data, not merely shown a screen it could skip. If you have a verified factor, any half-authenticated session is redirected to the challenge rather than allowed through.

Available on every plan, including Free. Security is not an upsell.

On a device with a passkey, Face ID or Touch ID is already how you unlock the passkey. Deeper native biometric integration arrives with the iOS and Android apps.

A passkey replaces your password. This is the other kind: a six-digit code on top of one. Worth doing if you sign in from a machine your passkey does not live on.

  1. Open Settings, then Security.

    Two-factor and passkeys live on the same page, which is deliberate: they solve overlapping problems and it should be obvious you have both.

    Open Security settings
  2. Scan the QR code with your authenticator app.

    Any TOTP app works: 1Password, Authy, Google Authenticator, your password manager. If you are already on your phone and cannot scan your own screen, copy the secret instead and paste it into the app.

  3. Type the six-digit code back to prove it took.

    Nothing is switched on until this succeeds. Abandoning the page here leaves nothing half-enabled: an unverified factor is removed rather than left lying around.

  4. Save the recovery codes. This is the step people skip.

    They appear once, at that moment, and are never shown again. They are the only way back in if you lose the phone, so put them where you keep passwords rather than in the same app you just enrolled.

Watch out

Once a factor is verified it is enforced: signing in leaves you at the code prompt before any page loads. That is the point of it, and the reason the recovery codes matter.

Similar readings

Everything below is in the Happiness Center.

Was this article helpful?