High-Level Summary
Add a passwordless signup path: user provides an email, verifies it, and enrolls a passkey. No passwords.
Motivation
- Google/GitHub excludes users whose work identity lives elsewhere or who can't/won't use social login.
- 100% of signups today depend on two third-party IdPs. An outage or policy change at either blocks acquisition/access.
- Going straight to passkeys avoids ever building a password stack.
- Passkeys are more secure
Goals
- User can sign up with email + passkey, no social IdP required, no password set.
- Email must be verified before the account can take any action on the platform (hard gate).
- Users can enroll, name, and revoke multiple passkeys.
- Defined recovery path when all passkeys are lost, without falling back to passwords.
- Existing social-login users can add a passkey, and the passkey can be used in place of the social IdP at sign-in.
- Downstream provisioning (org, membership, quota) is identical to social signup.
- Self-serve signup is protected against bots and abuse.
Non-Goals
No response
High-Level Summary
Add a passwordless signup path: user provides an email, verifies it, and enrolls a passkey. No passwords.
Motivation
Goals
Non-Goals
No response