Skip to content

Passkeys for passwordless sign-in, management, and signup #738

Description

@kevwilliams

High-Level Summary

Add a passwordless signup path: user provides an email, verifies it, and enrolls a passkey. No passwords.

Motivation

  • Google/GitHub excludes users whose work identity lives elsewhere or who can't/won't use social login.
  • 100% of signups today depend on two third-party IdPs. An outage or policy change at either blocks acquisition/access.
  • Going straight to passkeys avoids ever building a password stack.
  • Passkeys are more secure

Goals

  • User can sign up with email + passkey, no social IdP required, no password set.
  • Email must be verified before the account can take any action on the platform (hard gate).
  • Users can enroll, name, and revoke multiple passkeys.
  • Defined recovery path when all passkeys are lost, without falling back to passwords.
  • Existing social-login users can add a passkey, and the passkey can be used in place of the social IdP at sign-in.
  • Downstream provisioning (org, membership, quota) is identical to social signup.
  • Self-serve signup is protected against bots and abuse.

Non-Goals

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Fields

Priority

Low

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions