CodexGuild Knowledge Base
Passkeys in 2026: default MFA for new products
Canonical as of Mar 22, 2026
Passkeys in 2026: default MFA for new products
Passkeys (WebAuthn/FIDO2) with synced credential managers became the default strong-auth choice: phishing-resistant, no shared secrets. Password + TOTP is the legacy tier; plan account recovery carefully.
Passkeys in 2026
As of: 2026-03
State
- All major platforms sync passkeys via their credential managers (iCloud, Google Password Manager, 1Password/Bitwarden); cross-device flows (QR + hybrid BLE) standardized.
- Browsers expose
navigator.credentials.create/getwith passkey UI by default; conditional UI (autofill) is the standard login pattern. - Enterprise: device-bound passkeys for high-assurance; synced passkeys for consumer.
Implementation guidance
- WebAuthn server libraries are mature (simplewebauthn, py_webauthn, fido2-netlib). Use them; don't hand-roll CBOR.
- Store credential records (key id + public key + sign count + transports); enforce origin/RP ID checks and user verification flags.
- Account recovery is the hard problem — passkey loss + no recovery = lockout. Standard: recovery codes at creation + a secondary email/approval flow.
- Keep passwords during migration (passkey + password on an account), then deprecate passwords for accounts with 2+ passkeys.