# Set up two-factor sign-in and passkeys

Turn on two-factor sign-in with an authenticator app and backup codes, add passkeys, require them by role, and help a user who lost their device.

Two-factor sign-in (two-factor authentication, or 2FA, sometimes called MFA) asks for a six-digit code from an authenticator app after the password. A passkey signs you in with your fingerprint, face or device PIN. Administrators manage both on **BetterShield › Protect › Two-Factor**; everyone else uses their own profile screen.

## The summary at the top

Three tiles show **Your two-factor** (Off until you set it up), **Two-factor required for** and **Passkey-only sign-in for** (both no roles by default).

## Your sign-in: two-factor

The **Two-factor authentication** card:

1. Press **Set up two-factor**.
2. Open any authenticator app that makes six-digit codes, such as 1Password, Google Authenticator, Microsoft Authenticator, Authy or Bitwarden. Scan the QR code, or type the **Manual entry key**.
3. Enter the code the app shows and press **Confirm code**.
4. Store the ten backup codes (**Copy codes** or **Download as a file**). They are shown only once, and each works once.
5. Press the **I have stored these codes** button to turn two-factor on.

Nothing changes at sign-in until step 5. **Cancel** at step 3 discards the setup.

Once it is on, the card shows how many backup codes are unused. Under **New backup codes**, enter an **App code or backup code** and press **Issue new codes**; the new set replaces every old code. Under **Turn off**, enter a current code and press **Turn two-factor off**. Application passwords for connected tools keep working.

## Your sign-in: passkeys

On the **Passkeys** card, type **Name this device**, press **Add a passkey**, and confirm on your device. A passkey is an extra way in: your password, codes and recovery link keep working. Each account can hold 10. Passkeys need HTTPS; without it, the card says why. Each passkey shows when it was last used, and **Remove** deletes it after you confirm.

Once any account has a passkey, the WordPress sign-in page (wp-login.php) shows **Sign in with a passkey**. A passkey unlocked with a fingerprint, face or PIN counts as both factors. One that only asks for a touch still needs the app code on a two-factor account, and is not accepted on its own.

## What the site requires

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Require two-factor of a role** | Accounts in the ticked roles are asked to set up two-factor, with a countdown on every dashboard page. After the grace period, the dashboard sends them to set it up until they do. | Sign-in is never blocked: it is enforced in the dashboard, after the password, and safe mode stands it down. | No roles |
| **Grace period, in days** | 0 to 90, counted from when an account first met the requirement. Zero asks immediately. | Existing accounts get the full window. | 14 |
| **Sign in with a passkey only** | For ticked roles, an account's password stops signing it in once it has added a passkey. A line per role shows how many have one. | A password that cannot sign anyone in cannot be phished, guessed or reused from a breach. | No roles |

Press **Save requirement** under each. Adding a role to **Require two-factor of a role** first checks your recovery link or printed recovery codes, as a sign-in hardening fix does.

Passkey-only sign-in has these safeguards:

- Nobody is refused until they hold a passkey. Others keep their password and are asked on their dashboard.
- Adding a role is refused unless the site has a working recovery link or printed recovery codes (**Protect › Recovery**), and unless passkeys work on the site.
- A refused password gets a message pointing to the passkey button. XML-RPC needs an application password instead.
- If the passkey is lost, the recovery link, a printed recovery code, or removing the last passkey brings password sign-in back.

On a WooCommerce store, customers set up both on **My Account › Sign-in security**. A role WooCommerce keeps out of the dashboard is not asked by **Require two-factor of a role**, but can still set it up there.

## Set up from your profile

Anyone signed in can use their own **Profile** screen:

- **Two-factor sign-in**: **Set up two-factor**, scan the code or type the key, enter the **Code from the app**, press **Confirm code**, store the ten codes, then press the **I have stored these codes** button. Later, **Issue new backup codes** asks for a current code first.
- **Passkeys**: **Name this device**, then **Add a passkey**.

## Signing in

After the password, the **Authentication code** screen takes the app's current code or an unused backup code. After ten wrong codes in an hour, codes for that account are not checked for a while.

## When someone loses their device

1. They sign in with a backup code, then issue a new set.
2. If the codes are gone too, an administrator opens **Users**, edits the account, and under **Two-factor sign-in** presses **Turn off two-factor for this account**. The person signs in with their password and sets it up again.
3. For a passkey-only account, an administrator can untick its role under **Sign in with a passkey only**, which brings password sign-in back for that role. A role the network requires cannot be unticked on one site.

If you are locked out yourself, use your recovery link.

## Multisite

On **BetterShield › Network**, **Require two-factor across the network** (with its own **Grace period, in days**) and **Passkey-only roles across the network** set a floor for every site. A site can add roles but not remove the network's, and the shorter grace period applies. Adding a passkey-only role needs a working recovery link or printed codes on every site. Both start **Not set**.

## Related

- [Hardening](/docs/hardening/)
- [Locked out](/docs/locked-out/)
- [Your profile](/docs/your-profile/)
- [Sign-in policies](/docs/sign-in-policies/)
- [Install and set up](/docs/install-and-set-up/)
- [Support](/support/)
