Passkeys & MFA
Sign in without a password, or require a passkey as a second factor after your password or OIDC provider.
A passkey authenticates you through your phone, computer, or hardware key. Arcane supports:
- Passwordless sign-in — select Passkey on the login page and follow your device’s prompt to sign in without a password.
- Passkey MFA — sign in with your password or OIDC provider, then confirm with a passkey.
Registering a passkey does not turn on MFA. Enabling MFA is a separate switch.
Set APP_URL to your public HTTPS URL before registering passkeys. Its hostname becomes the WebAuthn relying party ID; the full URL supplies the origin. A missing hostname prevents startup, and passkeys won’t work at a different hostname. See Environment Variables.
Browsers only expose the WebAuthn API in a secure context, so passkeys need HTTPS (or localhost). On a plain-HTTP deployment Arcane shows “Passkeys require a supported browser and a secure HTTPS connection.” and hides the controls. See TLS or put Arcane behind a reverse proxy that terminates HTTPS.
Register a passkey
- Open Account from the sidebar user menu, on the Account tab.
- In the Passkeys section, select Add passkey.
- Give it a name you will recognize later — the device it lives on, usually.
- Complete the prompt your browser or operating system shows.
Each passkey is listed with its name and when it was last used. You can rename or delete any of them from the same section.
Register more than one. A passkey lives on a single device; if that device is your only way in and you lose it, you are relying on recovery codes.
Arcane prefers post-quantum ML-DSA keys when your authenticator supports them and falls back to classical algorithms otherwise.
Turn on passkey MFA
You need at least one registered passkey first — it becomes the second step.
- In the same Passkeys section, find Passkey MFA and select Enable MFA.
- Arcane generates 10 single-use recovery codes and shows them once, immediately.
- Save them somewhere secure before closing the message. They are the only way back in if you lose your passkey.
From then on, signing in with a password or through OIDC stops at an MFA step offering Use passkey or Use recovery code.
The panel shows how many recovery codes remain. Regenerate codes issues a fresh set of 10 and invalidates the old ones — the new codes are also shown only once.
Disabling MFA deletes your remaining recovery codes and leaves your passkeys registered, so sign-in falls back to password or OIDC alone.
If you lose both your passkeys and your recovery codes, an operator with shell access to the Arcane container can clear MFA for the account. See Account Recovery.
Confirm your identity before changes
Changes to passkeys, MFA, or recovery codes require Confirm your identity with a passkey or current password. Confirmation and individual passkey prompts expire after 5 minutes.
OIDC-only accounts need an accessible passkey for this step. Without one, use arcane admin reset-mfa as described in Account Recovery.
Use the CLI with MFA enabled
arcane-cli auth login uses a browser device flow, which cannot carry an MFA challenge, so it fails on an account with MFA enabled. Create a personal API key from the API keys section of the same Account page instead, then run:
Personal API keys inherit your role’s permissions. See CLI Configuration.
Related
- OIDC Single Sign-On — passkey MFA layers on top of OIDC sign-in.
- Roles & Permissions — what an account can do once it is in.