Overview

In the previous guide, we demonstrated how to add an MFA step to your Keycloak login flow using Authsignal.

In this guide, we will show you how to enable a passkey authenticator so that users can enroll a passkey using Authsignal’s prebuilt UI.

Add passkey to the sign-in flow.

Authsignal configuration

Setup a custom domain

In this demo, we are going to use the pre-built UI for passkey enrollment. Passkeys are associated with a domain, so we recommend setting up a custom domain at this point. See our guide on setting up a custom domain for instructions.

Add a custom domain

Enabling a passkey authenticator

Enable a Passkey Authenticator on your tenant in the Authsignal Portal.

Enable a Passkey Authenticator

Once users have enrolled a Passkey, they will be able to complete the MFA step using their passkey with the prebuilt UI.

Passwordless sign-in via Authsignal pre-built UI using passkey.

To allow users to add a passkey, you could also add a button to an authenticated page - read more in our guide on Authenticator Binding with Pre-built UI.

In the next guide, we will demonstrate how to setup Passkey autofill which will allow users to sign-in by simply clicking the input and authenticating with their passkey.