Actions
User Story #237
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
User Story #237:
As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Start date:
09/06/2026
Due date:
% Done:
100%
Estimated time:
(Total: 0:00 h)
Description
As a user, I want to log in using a security key (WebAuthn/passkey), so that I can use phishing-resistant MFA.
Security keys are one of several MFA methods a user can enroll (alongside TOTP). Used strictly as a second factor, after password โ not a passwordless/usernameless login (that is a separate future story).
Acceptance:
- User can register one or more security keys from their profile, each given a name by the user
- User can view their registered keys (name, date added, last used) and revoke any of them individually
- At the MFA step of login, if a user has a security key enrolled, they can use it to complete sign-in; if they have more than one MFA method enrolled, they choose which to use
- Login flow handles cancellation, no matching key present, and unsupported browser gracefully, with a clear message and a way to fall back to another enrolled method
- Existing TOTP recovery codes remain the single recovery path if a user loses access to their key(s)
- A cloned/duplicated authenticator is detected and rejected on sign-in
Actions