Skip to main content
Users may want to remove authentication methods for various reasons:
  • Switching to a new device or authenticator app
  • No longer having access to an email or phone number
  • Simplifying their authentication setup
The Authsignal pre-built UI provides a secure, user-friendly way for users to remove authenticators.

Implementation steps

1. Backend: Track action with settings redirect Passing redirectToSettings: true in the track request will mean that after completing a challenge with an existing authentication method, users will be redirected to a settings menu where they can remove authentication methods.
2. Frontend: Launch settings flow
3. User experience Users will:
  1. Complete a challenge with one of their existing authenticators
  2. Access the settings menu where they can view all their enrolled methods
  3. Remove unwanted authenticators
Removing authentication methods in the pre-built UI

Removing authentication methods in the pre-built UI

The pre-built UI automatically enforces security by requiring authentication before allowing removal. Users cannot remove their last remaining authenticator to prevent account lockout.

Preventing removal of the last passkey

By default, users can remove their only passkey if they have another authentication method. To stop this, turn on Prevent removing last passkey in the advanced settings of the passkey authenticator. You can also set preventRemovingLastPasskey with the Management API. When the setting is on, the pre-built UI doesn’t offer to remove the user’s last passkey, and the Client API refuses to remove it. Admins can still remove it from the Portal, and the Server API is not affected.

Administrative removal

Admins can remove authenticators for users through the Authsignal Portal:
  1. Navigate to the Users section
  2. Search for and select the user
  3. Scroll down to see the enrolled authenticators
  4. Remove specific methods as needed

Next steps