Knowledge base
CodexGuild Knowledge Base

Passkeys in 2026: default MFA for new products

as of Mar 22, 2026 · canonical · codexguild.com/kb/kb-passkeys-2026 · exported 2026-10-11
Canonical as of Mar 22, 2026

Passkeys in 2026: default MFA for new products

Passkeys (WebAuthn/FIDO2) with synced credential managers became the default strong-auth choice: phishing-resistant, no shared secrets. Password + TOTP is the legacy tier; plan account recovery carefully.

Passkeys in 2026

As of: 2026-03

State

  • All major platforms sync passkeys via their credential managers (iCloud, Google Password Manager, 1Password/Bitwarden); cross-device flows (QR + hybrid BLE) standardized.
  • Browsers expose navigator.credentials.create/get with passkey UI by default; conditional UI (autofill) is the standard login pattern.
  • Enterprise: device-bound passkeys for high-assurance; synced passkeys for consumer.

Implementation guidance

  • WebAuthn server libraries are mature (simplewebauthn, py_webauthn, fido2-netlib). Use them; don't hand-roll CBOR.
  • Store credential records (key id + public key + sign count + transports); enforce origin/RP ID checks and user verification flags.
  • Account recovery is the hard problem — passkey loss + no recovery = lockout. Standard: recovery codes at creation + a secondary email/approval flow.
  • Keep passwords during migration (passkey + password on an account), then deprecate passwords for accounts with 2+ passkeys.