← All features
Passkeys

Sign in with a touch.

Sign in to WordPress without entering a username or password. Use Touch ID, Windows Hello, a security key or a compatible password manager.

New in FluentAuth 3.0.

Why it matters

Skip the username and password.

With a registered passkey, your team can sign in directly. Choose passkey login, approve the device prompt and get back to work without typing login details.

How it helps your site

Verification tied to your site.

Passkeys use a credential bound to your domain. A lookalike site cannot request the same credential for its own domain, and approval happens through a registered authenticator. Your fingerprint or face scan is not sent to WordPress.

What you gain

Your team gets a familiar device prompt and a direct route into WordPress. Your site verifies the registered passkey to sign in the right account.

Get FluentAuth →
Inside FluentAuth

See the controls behind the experience.

New in FluentAuth 3.0.

Follow the setup guide →
FluentAuth settings showing passkey, authenticator app and email verification options.
FluentAuth settings showing passkey, authenticator app and email verification options. Select the image to view it full size.

How passkeys work in FluentAuth

  1. Enable passkeys as an allowed two-factor method for the roles you select.
  2. Each user registers their own compatible device, security key or password manager.
  3. On the login page, select Log in with passkey without entering a username or password.
  4. Choose the saved passkey for your account and approve the device prompt to sign in.

This is discoverable passkey sign-in: your browser or password manager finds the saved credential for the site, and FluentAuth uses it to identify and sign in your account. Passkeys can also provide device verification in other login flows.

A practical choice for administrators

Start with the people who install plugins, edit site settings and manage other accounts. Enrol one administrator, test their normal login flow, then extend the policy to the rest of the team.

What if someone loses their device?

Keep a fallback before requiring passkeys: recovery codes, an authenticator app or a second passkey. A lost device should not leave your team without a way back in. Passkeys also need HTTPS and a compatible browser and authenticator.

Give your team a simpler sign-in.

Turn passkeys on, then follow the enrolment guide to prepare a tested rollout.