I have enabled passkeys for my customers. After signing up, a customer can now set up a passkey. However, if they do so, they are no longer required to create a password.
Is it possible to require customers to always create a password during sign-up, while keeping the passkey as an optional additional authentication method?
Hi @Alois.Goeth
Thank you for reaching out to us!
I understand that you are asking whether Auth0 can require customers to create a password during sign-up while keeping Passkeys as an optional additional authentication method.
Based on our Support Article on how to Configure User Account with Both Passkey and Password, it appears that by default it is not possible to require users to setup a password during the sign-up the way you intend in your flow, however you can allow your users to setup their password before their Passkey.
Root Cause:
Passkeys in Auth0 are implemented as an Authentication Method (a primary way to access an account), not as a secondary Multi-Factor Authentication (MFA) factor. When passkeys are enabled on a connection, Auth0 treats them as an alternative to passwords rather than an addition to them. The current behavior is that once a user enrolls in a passkey, the password becomes optional—the opposite of what you need.
Official Workaround:
If your use case allows it, you can achieve a similar outcome using WebAuthn as an MFA factor instead of passkeys as an authentication method. With this approach:
- Users are required to create a password during sign-up (standard behavior).
- After their first login, an Auth0 Action can prompt them to enroll in WebAuthn with Device Biometrics as an optional MFA factor.
- On subsequent logins, users can authenticate with either their password or the WebAuthn factor.
This gives you the security benefit of passwordless authentication while maintaining password as the primary credential and keeping WebAuthn optional.
We hope this clarifies the current limitations. Please reach out to us for any other issues or requests, we will gladly look into it!
Have a great one,
Gerald