Adding a passkey makes it mandatory as MFA on other devices

(#1377) Feature Shipped security

Observed behaviour

After adding a passkey on one PC, I tried to log in from a different PC using email + password. Fluxer then required the passkey as a second authentication factor. The passkey was stored on the first PC and was not available on the second one, so I was effectively unable to log in from the new device. TOTP/2FA was disabled. Simply adding a passkey caused Fluxer to start requiring WebAuthn after password authentication. A passkey should be an alternative login method, not automatically become a mandatory second factor for password logins. I should still be able to log in with email + password when TOTP/2FA is disabled, even if a passkey is registered on another device.

Reproduction steps

  1. On PC A, use an account with TOTP/2FA disabled.
  2. Add a passkey stored locally on PC A.
  3. On PC B, where that passkey is not available, open Fluxer.
  4. Log in using the same email and password.
  5. Fluxer requires the passkey as MFA.
  6. Login cannot be completed because the passkey only exists on PC A.

Build information

Canary Desktop 2026.811.124022, Stable Web 2026.812.122910, Windows 11 10.0.26200 (x64), Electron 41.2.2, Chrome 146.0.7680.188, Node 24.14.1, Locale fr

Affected surface

Web app, Desktop app

Instance

Self-hosted, PostgreSQL 16, FLUXER_IMAGE_TAG=v1

10 comments

Sign in with Fluxer to comment and vote.
Comment by Hampus
HampusStaff 1 vote originally by @hampus-fluxer on GitHub 4 replies
This is not a bug report but is a feature request to potentially allow instances to configure whether WebAuthn is a two-factor authentication method or not. Fluxer has made the decision, like Discord, that WebAuthn is a two-factor authentication method, and it is implemented as such. If it weren't required to login to your account, but you could just use an email and password, it is not two-factor authentication and it provides zero extra security. It only provides convenience. That may be a valid way someone wants their instance to work, however, and it is worth discussing as a feature request.
Comment by @Victor-root
RexSystem 1 vote originally by @Victor-root on GitHub OP
I understand that WebAuthn is intentionally treated as MFA. The problem I'm pointing out is that this can completely block login on another device if the registered passkey is device-bound. Example:
  • PC A: account has a locally stored passkey
  • PC B: that passkey is not available
  • TOTP is disabled
  • I enter the correct email and password on PC B
  • Fluxer then requires the passkey from PC A, so I cannot log in at all
So this is not just about convenience. Registering a device-bound passkey on one machine can make the account inaccessible from another machine unless the user has already configured another MFA method.
Comment by Hampus
HampusStaff 1 vote originally by @hampus-fluxer on GitHub
I believe you should have been offered the option to download backup codes when setting up WebAuthn as an MFA method. When you cannot access a specific MFA method, it is intentional that you cannot login to your account, since you do not have access to the MFA method in question. Otherwise it is not MFA. But with backup codes, you should be able to sign in to your account anyway. Let me know if this is not working as you expect, however, but this would be the solution to your problem at this time, aside from not using device-bound passkeys. Passkeys generally are a very poor UX and I wouldn't recommend them to most people. I'm open to practical suggestions, however.
Comment by @Victor-root
RexSystem 1 vote originally by @Victor-root on GitHub OP
I think we're talking past each other, my issue is not about recovery or backup codes. I did NOT enable two-factor authentication. I only added a passkey as an authentication method. Registering a passkey should not implicitly opt me into mandatory password + WebAuthn MFA unless I explicitly choose to enable that. A passkey can be used as a primary authentication method; registering one does not inherently mean the user wants it enforced as a second factor for password logins. The lockout on my second PC is just the consequence of that unexpected behaviour.
Comment by @Artimba
RexSystem 1 vote originally by @Artimba on GitHub
I get the confusion here. I am an avid passkey user (between a yubikey and bitwarden), and see why having 2FA disabled would lead to the belief that the passkey is just an alt auth method. Bitwarden passkey's offer a convenience to many platforms, while my yubikey is a security device. With more password managers adding support for them, I see this becoming a more common frustration. The ability to add a passkey while 2FA is disabled is strange if the intended behavior is that passkeys MUST be 2FA. I would imagine adding a passkey immediately toggles on 2FA and disables the button in that case (or pops up a modal warning the user about the passkey when trying to disable 2FA with one). Also its sad hearing that passkeys are considered bad UX. I thought they were one of the greatest things to happen with password managers.
Comment by @Septicity
RexSystem 1 vote originally by @Septicity on GitHub
Even in the more useful context of passkeys that are stored on mobile devices, this setup has made it impossible to log in on Firefox, since Firefox (at least on desktop) doesn't support any type of passkey other than physical security keys or hardware passkey interpreters. Since making an exception doesn't make sense, I think it may be necessary to allow authentication from outside sessions on all platforms instead of just the desktop app.
Comment by @nwenny
RexSystem 1 vote originally by @nwenny on GitHub
This really seems like unintended behavior. I set up a passkey on my phone to make it easier to log in on mobile, and I expected this to only be for my phone. The reality is that it's now a passkey for all my devices, and obviously that's not something that works. I can't log in on my laptop anymore, and I can't set up 2FA because it wants a passkey that my computer does not have. I tried deleting the passkey and I can't because it errors. I'm relatively new to adding passkeys to my accounts, but I don't think I've ever seen a passkey implemented this way in anything I've ever touched. I enjoy using Fluxer but this is frustrating and a little alarming. If I get locked out of my desktop, I lose the primary way I 1. use Fluxer and 2. talk to a partner. A passkey shouldn't be used as mandatory 2FA unless that's explicitly enabled by the user. At the very minimum a warning should be there stating that this is 2FA and not just an alternative login method. Much more important edit: Oh to add to this, the passkey doesn't even work. It doesn't do anything on my phone. So I couldn't do anything about this if I tried. I'm too nervous paying for a subscription to an account I could just randomly lose access to and never get back into, so I'm gonna have to cancel that until something changes.
Comment by Hampus
HampusStaff 1 vote originally by @hampus-fluxer on GitHub
I will add a toggle to make you opt-in to using it as two-factor authentication. I've tried to make it clear in the UI that it's a two-factor authentication method, but I haven't made it clear enough. I can also see why people would like to use it not as two-factor authentication, it's just a bit of work to ensure this change is rolled out safely. This fix will be available within the next few hours. For anyone currently having issues accessing their account, feel free to email support@fluxer.com and we'll get it sorted.
Comment by Hampus
HampusStaff 1 vote originally by @hampus-fluxer on GitHub
For reference, the change that rolled out is #2857. Adding a passkey no longer turns it into a second factor. Passkeys work as a way to sign in without a password, and using one as two-factor authentication is a separate opt-in: the "Require a passkey as your second factor" toggle in the Passkeys section of your security settings. Accounts that had a passkey registered before this change kept it switched on, so nobody's security was quietly lowered. If you added a passkey without meaning to use it as 2FA, sign in on the device that has it (or with a backup code) and turn that toggle off. After that, email and password works on any device again.