Articles in this section

How to use a Passkey as a Two-Factor Authentication (TFA) option in BoldSign?

Published:

If you have a registered passkey, BoldSign can use it as an additional identity verification method during sign-in. This applies whether you sign in with your email address and password or through an external identity provider, such as Google, Microsoft, Apple, or your organization’s Single Sign-On (SSO) provider.

Using a passkey provides a fast and secure alternative to authentication codes delivered through authenticator apps, SMS, or email.

Prerequisites

Before using a passkey as a TFA method, ensure that:

  • You have registered at least one passkey in your BoldSign account.

How sign-in flow changes depending on your account setup?

BoldSign supports two sign-in methods:

  • A) Standard sign-in using an email address and password
  • B) External sign-in using Google, Microsoft, Apple, or your organization’s SSO provider

The authentication flow after your primary credentials are verified depends on whether you have a registered passkey and whether TFA is enabled.

A. Standard sign-in (email address and password)

  1. Open the BoldSign sign-in page.

  2. Enter your account email address and password, then click Sign In.

  3. Based on your account configuration, one of the following authentication flows occurs:

    Your account setup What happens next
    TFA enabled (Authenticator App, SMS, or Recovery Email) — with or without a passkey registered You are taken to the Two-Step Verification screen. If a passkey is registered, Passkey appears as one of the selectable options alongside Authenticator App, SMS, and Recovery Email.
    No TFA enabled, but a passkey is registered You are taken directly to the Verify Identity screen, where you can choose either Passkey or Email OTP to verify your identity.
    No TFA and no passkey registered You are signed in directly. No additional verification step is shown.
Login options.jpg

  1. If the Two-Step Verification or Verify Identity screen appears and you select Passkey:
    • When prompted by your browser or operating system, complete authentication using your configured biometric method (fingerprint, facial recognition), device PIN, or physical security key.
    • After successful verification, you are signed in immediately.

The session duration screen (30 days or 30 minutes) is not displayed when using a passkey after a password sign-in because the session preference was already selected during the sign-in process.

Email OTP Fallback

The email OTP fallback screen appears only when a passkey is not registered and no configured TFA method is available to complete a required verification step. For example, this can occur when your organization requires TFA but no authenticator app, SMS verification, recovery email, or passkey has been configured.

B. External / SSO Sign-in (Google, Microsoft, Apple, or organization SSO)

  1. Open the BoldSign sign-in page.

  2. Select one of the available external sign-in options:

    • Continue with Google
    • Continue with Microsoft
    • Continue with Apple
    • Your organization’s Single Sign-On (SSO) option
  3. Complete authentication with the external identity provider by entering your credentials or using an existing authenticated session.

  4. After successful authentication, BoldSign checks your account configuration.

    Your account setup What happens next
    Passkey registered on the account You are redirected to the Verify Identity (passkey) screen to complete a passkey challenge.
    No passkey registered You are redirected directly to the session duration screen (30 days / 30 minutes), then signed in.
  5. If prompted for the passkey challenge:

    • Complete authentication using your configured biometric method, device PIN, or physical security key.
    • After successful verification, the Session Duration screen (30 days / 30 minutes) appears before you are signed in.

For external or SSO sign-in, the passkey challenge acts as an additional identity verification step after the external provider has authenticated you. Unlike standard sign-in, the passkey is not displayed as a selectable TFA option alongside Authenticator App, SMS, or Recovery Email methods.

Using a passkey stored on another device for TFA

If your passkey is stored on a mobile device and you are signing in from a desktop browser:

  1. Select Passkey on the Two-Step Verification screen.
  2. Choose the option to use a phone or tablet.
  3. Scan the displayed QR code with your mobile device.
  4. Complete authentication on your mobile device using biometric verification or your device PIN.

Ensure Bluetooth is enabled on both devices and that they are located near each other.

Troubleshooting

  1. What should I do if passkey verification fails or the prompt is closed?
    Click Try another way on the verification screen and select another available verification method, such as:

    • Authenticator App
    • SMS verification
    • Recovery Email
  2. Why don’t I see the Passkey option on the verification screen?

    • The Passkey option is displayed only when at least one passkey has been registered in:
      Settings > My Profile > Passkeys
  3. Passwordless sign-in vs. TFA sign-in — what’s the difference in session behavior?

    • Passwordless sign-in: You select Sign in with passkey directly on the sign-in page without entering a password. After successful verification, you are prompted to choose a session duration (30 days or 30 minutes).
    • Passkey-based TFA: You first sign in using your email address and password. After successful passkey verification, you are signed in immediately without a session duration prompt.
  4. What identity verification is required when registering or removing a passkey?
    The identity verification method depends on your account configuration:

    • If Two-Factor Authentication (TFA) is configured, the verification process uses your configured TFA method (Authenticator App, SMS, or Recovery Email).
    • If TFA is not configured, BoldSign sends a one-time password (OTP) to your account’s primary email address for verification.
Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
Access denied
Access denied