Skip to content

Passkeys & MFA

Sign in without a password, or require a passkey as a second factor after your password or OIDC provider.

A passkey authenticates you through your phone, computer, or hardware key. Arcane supports:

  • Passwordless sign-in — select Passkey on the login page and follow your device’s prompt to sign in without a password.
  • Passkey MFA — sign in with your password or OIDC provider, then confirm with a passkey.

Registering a passkey does not turn on MFA. Enabling MFA is a separate switch.

Browsers only expose the WebAuthn API in a secure context, so passkeys need HTTPS (or localhost). On a plain-HTTP deployment Arcane shows “Passkeys require a supported browser and a secure HTTPS connection.” and hides the controls. See TLS or put Arcane behind a reverse proxy that terminates HTTPS.

  1. Open Account from the sidebar user menu, on the Account tab.
  2. In the Passkeys section, select Add passkey.
  3. Give it a name you will recognize later — the device it lives on, usually.
  4. Complete the prompt your browser or operating system shows.

Each passkey is listed with its name and when it was last used. You can rename or delete any of them from the same section.

Register more than one. A passkey lives on a single device; if that device is your only way in and you lose it, you are relying on recovery codes.

Arcane prefers post-quantum ML-DSA keys when your authenticator supports them and falls back to classical algorithms otherwise.

You need at least one registered passkey first — it becomes the second step.

  1. In the same Passkeys section, find Passkey MFA and select Enable MFA.
  2. Arcane generates 10 single-use recovery codes and shows them once, immediately.
  3. Save them somewhere secure before closing the message. They are the only way back in if you lose your passkey.

From then on, signing in with a password or through OIDC stops at an MFA step offering Use passkey or Use recovery code.

The panel shows how many recovery codes remain. Regenerate codes issues a fresh set of 10 and invalidates the old ones — the new codes are also shown only once.

Disabling MFA deletes your remaining recovery codes and leaves your passkeys registered, so sign-in falls back to password or OIDC alone.

If you lose both your passkeys and your recovery codes, an operator with shell access to the Arcane container can clear MFA for the account. See Account Recovery.

Changes to passkeys, MFA, or recovery codes require Confirm your identity with a passkey or current password. Confirmation and individual passkey prompts expire after 5 minutes.

OIDC-only accounts need an accessible passkey for this step. Without one, use arcane admin reset-mfa as described in Account Recovery.

arcane-cli auth login uses a browser device flow, which cannot carry an MFA challenge, so it fails on an account with MFA enabled. Create a personal API key from the API keys section of the same Account page instead, then run:

Terminal window
arcane-cli config set api-key <key>

Personal API keys inherit your role’s permissions. See CLI Configuration.