Skip to content
Version v3.2.0

Passkey policy option reference ​

This reference describes every UserStore IDP option used by the current passkey policy. Read UserStore passkeys first if you are selecting an operating model or planning a rollout.

Option names and enum values are case-sensitive. Durations are integer seconds unless the option name explicitly says milliseconds. List values accept comma, semicolon, or newline separators and are normalized by ProAuth.

TIP

Use GET /api/management/v2/idpinstances/{idpInstanceId}/passkey-policy to inspect the effective typed policy. Use the policy preview endpoint before writing options so that defaults, legacy precedence, cross-option constraints, impact, and approval requirements are evaluated together.

Enablement and login experience ​

OptionValues and defaultPurpose and guidance
PasskeyEnabledBoolean; default falseEnables UserStore login-passkey registration and authentication. Enabling this option alone does not remove passwords or require enrollment.
PasskeyLoginExperienceButton, ConditionalAndButton (default), PasskeyFirstControls presentation on the login page. Button requires an explicit action. ConditionalAndButton also permits browser autofill/conditional UI. PasskeyFirst starts with passkey authentication while retaining policy-allowed alternatives.
PasskeyEnrollmentPolicyOptional (default), Encouraged, RequiredDetermines whether enrollment is available, promoted, or mandatory. Required is normally combined with a non-zero grace period for existing users.
PasskeyEnrollmentGracePeriodSeconds0–31536000; default 0Time allowed to satisfy required enrollment before policy enforcement. 0 means no grace period. A password-prohibited required-enrollment policy also needs an operational initial-enrollment route.
PasskeyAuthenticatorTimeoutSeconds30–600; default 180Timeout sent to the browser for WebAuthn ceremonies. It is a client hint, not a replacement for server-side challenge expiry and single-use consumption.

PasskeyFirst changes presentation, not assurance. A failed or cancelled passkey attempt exposes only alternatives permitted by the effective password, enrollment, and recovery policy.

Credential inventory and maturation ​

OptionValues and defaultPurpose and guidance
PasskeyMaxCredentialsPerUser1–50; default 20Maximum active login passkeys for one user, checked when registration starts and completes. Keep enough capacity for replacement and device turnover.
PasskeyRequiredCredentialCount1–10, and no greater than PasskeyMaxCredentialsPerUser; default 1Minimum number of usable credentials required by readiness. For managed passwordless deployments, 2 protects against loss of one device.
PasskeyCredentialDiversityPolicyDistinctCredential (default), DistinctAaguid, DistinctMetadataVendor, DistinctTrustRootDefines how the required credential count must be diversified. Stronger evidence-based modes require the corresponding attestation or metadata evidence.
PasskeyCredentialMaturationSeconds0–2592000; default 86400 (24 hours)Delay before a newly bound credential can satisfy destructive-action readiness. It limits the value of binding a credential and immediately using it to remove recovery paths.
PasskeyExistingCredentialEnforcementGrandfather (default), GraceThenRestrict, BlockImmediatelyControls credentials that do not satisfy a newly tightened policy. See the behavior table below.

Credential diversity ​

ValueRequirement
DistinctCredentialEach credential ID is different. This prevents duplicate counting but does not prove separate devices or vendors.
DistinctAaguidCredentials must have distinct authenticator AAGUIDs. Credentials without usable AAGUID evidence cannot satisfy the distinction.
DistinctMetadataVendorCredentials must have distinct FIDO metadata statement evidence. Use when vendor independence is part of the control objective.
DistinctTrustRootCredentials must chain to distinct attestation trust roots. This is the strictest built-in evidence-diversity mode.

Existing-credential enforcement ​

ValueBehavior
GrandfatherAn UnknownLegacy credential can remain usable even when historical RP ID, algorithm, or trust evidence cannot be reconstructed. Mandatory compromise evidence still blocks it.
GraceThenRestrictA non-compliant credential remains usable only until its enforcement deadline. Use this for staged tightening with measurable remediation.
BlockImmediatelyA credential must satisfy the current policy now. Use only after an impact assessment confirms users retain a usable path.

Password lifecycle ​

OptionValues and defaultPurpose and guidance
PasskeyPasswordPolicyCoexist (default), UserRemovable, RemoveWhenReady, ProhibitedControls whether passwords remain, can be removed by the user, are removed by policy after readiness, or are prohibited.
PasskeyPasswordRemovalGracePeriodSeconds0–2592000; default 0Delay between scheduling and committing password removal. Readiness is evaluated again at commit. Use a non-zero period for managed migrations.
PasskeyPasswordRecreationPolicyAllowedAfterStrongAuthentication (default), RecoveryOnly, ProhibitedDetermines whether an absent password can be recreated. Passkey deletion itself never recreates a password.
PasskeyAdministrativeLastCredentialRemovalPolicyBlock (default), EnterRestrictedRecoveryControls authorized administrative handling of the last usable credential. Self-service deletion of the final credential is always blocked. Confirmed compromise revocation always proceeds.

Password policy values ​

ValueBehavior
CoexistPassword and passkey remain ordinary sign-in methods. Password security remains part of the account's effective security.
UserRemovableA user can explicitly request password removal after the server reports full readiness.
RemoveWhenReadyProAuth schedules password removal after readiness and commits it after the configured grace period if final readiness still succeeds.
ProhibitedPassword login and password recreation are unavailable. Existing users transition only through the configured migration and readiness process; newly provisioned users start in initial enrollment.

RemoveWhenReady and Prohibited require at least one recovery route, at least one verified security contact, and PasskeySecurityNotificationMode=Required.

Password recreation values ​

ValueBehavior
AllowedAfterStrongAuthenticationA policy-accepted strong authentication flow may establish a new password. Use only where returning to password login is an intentional product behavior.
RecoveryOnlyPassword recreation is possible only as an outcome of the governed recovery process.
ProhibitedNo passkey or recovery operation can reactivate password login.

User verification and sensitive-operation authentication ​

OptionValues and defaultPurpose and guidance
PasskeyUserVerificationPolicyRequired (default), PreferredWithMfaControls the WebAuthn user-verification request. Required requires authenticator verification such as a PIN or biometric. PreferredWithMfa requests verification when available and relies on the complete authentication chain for required assurance.
PasskeyBindingAuthenticationPolicyRecentAny, CurrentMaximumAal (default), PhishingResistantAuthentication evidence required before binding a new passkey or authorizing password removal.
PasskeyBindingAuthenticationMaxAgeSeconds0–3600; default 300Maximum age of the authentication used for credential binding. 0 effectively requires authentication at the current instant and is rarely operationally useful.
PasskeyDeletionAuthenticationPolicyRecentAny, CurrentMaximumAal (default), PhishingResistantAuthentication evidence required for self-service credential deletion. It does not prevent emergency administrative compromise revocation.
PasskeyTimestampDriftToleranceMilliseconds0–60000; default 0Explicit tolerance for timestamp comparisons in supported ceremony checks. Increase only for a measured clock-skew requirement; synchronize server clocks instead.

Authentication evidence levels ​

ValueEvidence accepted within the maximum age
RecentAnyAny recorded authentication method. This is the least restrictive value.
CurrentMaximumAalA user-verified passkey (pop and user AMR), or a fresh password where the specific binding workflow explicitly allows it.
PhishingResistantA user-verified passkey plus a phr or phrh ACR earned by the complete authentication chain.

Authenticator class and attestation ​

OptionValues and defaultPurpose and guidance
PasskeyAuthenticatorClassPolicyAny (default), BackupEligibleRequired, BackedUpRequired, DeviceBoundOnlySelects whether synced credentials, backed-up credentials, or only device-bound credentials can be usable.
PasskeyAttestationConveyancenone (default), indirect, direct, enterpriseWebAuthn attestation conveyance requested during registration. Do not request identifying attestation without a documented need and privacy assessment.
PasskeyAttestationTrustPolicyNone (default), MetadataIfAvailable, MetadataRequired, AaguidAllowListDetermines which attestation and FIDO metadata evidence a credential must have. A value other than None cannot be combined with conveyance none.
PasskeyAllowedAaguidsAAGUID list; default emptyAllow-list used by AaguidAllowList. The list must contain at least one value in that mode. Also useful as an explicit trust overlay.
PasskeyBlockedAaguidsAAGUID list; default emptyAuthenticator models that baseline risk evaluation must block. Allowed and blocked sets cannot overlap.
PasskeyUndesiredAuthenticatorStatusPolicyWarn, BlockNew (default), BlockAllResponse to an undesirable authenticator status from authoritative metadata. Mandatory compromise statuses cannot be ignored.

Authenticator class values ​

ValueEligible credential
AnySynced, backed-up, and device-bound credentials are accepted if other controls pass.
BackupEligibleRequiredThe authenticator reports that the credential can be backed up or synced.
BackedUpRequiredThe credential is backup-eligible and currently reports a backed-up state.
DeviceBoundOnlyThe credential is neither backup-eligible nor backed up. Use for managed hardware policies.

Attestation trust values ​

ValueRequirement
NoneAttestation and metadata are not required for usability. Other baseline checks still apply.
MetadataIfAvailableMetadata is evaluated when present; compromised metadata blocks the credential, but absence alone does not.
MetadataRequiredAttestation must be verified and the credential must have trusted FIDO metadata evidence.
AaguidAllowListAttestation must be verified and the AAGUID must be in PasskeyAllowedAaguids.

Required trust needs certificate-backed attestation validated against the authenticator's FIDO metadata trust roots. An AAGUID lookup alone is not proof of authenticator identity: none and self-attestation cannot satisfy MetadataRequired or AaguidAllowList. Under MetadataIfAvailable, those credentials may still register, but are recorded as untrusted and cannot later satisfy a required-trust policy without new verified enrollment.

Algorithms ​

OptionValues and defaultPurpose and guidance
PasskeyAllowedAlgorithmsCOSE algorithm identifiers; default -7,-35,-36,-37,-38,-39,-257,-258,-259Customer-narrowable allow-list intersected with the server-supported safe set. At least one supported value is required. Narrow only after verifying every supported authenticator.
COSE IDAlgorithm
-7ES256
-35ES384
-36ES512
-37PS256
-38PS384
-39PS512
-257RS256
-258RS384
-259RS512

EdDSA/Ed25519 is not in the current server-supported safe set and is not offered during registration.

Runtime risk and counter handling ​

OptionValues and defaultPurpose and guidance
PasskeySignatureCounterAnomalyPolicyRiskEvaluate (default), Hold, BlockResponse to a genuine regression of a previously non-zero authenticator signature counter. Authenticators that consistently report zero remain valid.
PasskeyRiskProviderModeBaselineOnly (default), OptionalProvider, RequiredProviderDetermines whether an external IPasskeyExternalRiskProvider contributes to credential binding, counter anomalies, and backup-state changes. Baseline rules cannot be disabled.
PasskeySuspiciousBindingHoldSeconds0–604800; default 0Hold duration for a suspicious binding decision. A held credential cannot satisfy authentication or readiness until the hold is cleared or expires.

Risk provider behavior ​

ModeProvider absent or fails
BaselineOnlyNo external provider is called; non-disableable ProAuth baseline rules decide.
OptionalProviderThe operation is held rather than treated as approved without evidence.
RequiredProviderCredential binding or the evaluated operation is blocked.

Signature-counter behavior ​

ValueResult for a genuine non-zero regression
RiskEvaluateSend the event through the configured risk-provider path. If no optional provider is available, the result is a hold.
HoldPlace the credential in an investigation hold.
BlockBlock the credential operation immediately.

Relying party and origins ​

OptionValues and defaultPurpose and guidance
PasskeyRpIdDNS relying-party ID; default derived from BaseServiceSettings:HostUrlCryptographic scope of the credential. It must equal the ceremony host or be its registrable-domain suffix. Do not change it directly while active credentials exist.
PasskeyRpNameString; default ProAuthHuman-readable relying-party name shown by authenticators when supported. It is not a security boundary.
PasskeyAllowedOriginsOrigin list; default emptyAdditional exact ceremony origins. Values must be HTTPS origins without credentials, paths, queries, or fragments. HTTP is accepted only for loopback development. During RP migration this list can contain the verified overlap origins.

Origins are canonical authorities such as https://login.example.com; https://login.example.com/account is invalid. An allow-list entry does not by itself authorize an unrelated RP ID: the ceremony selector also verifies the exact RP/origin binding.

Use the API-driven RP ID migration instead of replacing PasskeyRpId on an active deployment.

Security contacts, notifications, and retention ​

OptionValues and defaultPurpose and guidance
PasskeySecurityNotificationModeDisabled, BestEffort (default), RequiredControls durable notification requirements for credential and password lifecycle events. Password-removing policies require Required.
PasskeyRequiredVerifiedSecurityContactCount0–5; default 0Number of verified, non-revoked security contacts required for readiness. Password-removing policies require at least 1.
PasskeyRevokedCredentialRetentionSeconds0–31536000; default 7776000 (90 days)Retention period for non-reactivatable credential tombstones before purge. Align with investigation, privacy, and audit-retention requirements.

Security contacts are UserStore-scoped security records, not arbitrary user-profile strings. A confirmed legacy email address can be backfilled as a provenance-marked verified contact; an unconfirmed address is not migrated.

Recovery and initial enrollment ​

OptionValues and defaultPurpose and guidance
PasskeyRecoveryRoutesVersioned JSON route set; default {"Version":1,"Routes":[]}Alternative proof combinations accepted for account recovery. At least one route is required when passwords may be removed or are prohibited.
PasskeyInitialEnrollmentRoutesVersioned JSON route set; default {"Version":1,"Routes":[]}Alternative proof combinations accepted before a user with no primary authenticator binds the first passkey. Required for password-prohibited required enrollment.
PasskeyRecoveryCodeCount1–20; default 10Number of primary recovery codes generated when a user rotates the set. Rotation invalidates the previous set.
PasskeyRecoveryEmailTokenLifetimeSeconds60–86400; default 900Lifetime of a verified-contact recovery token.
PasskeyTemporaryAccessPassLifetimeSeconds60–86400; default 3600Lifetime of an operator-issued TAP. Approval and redemption must complete before expiry.
PasskeyRecoverySessionLifetimeSeconds300–3600; default 900Lifetime of the restricted session issued after recovery proof succeeds. It can bind a new primary authenticator but cannot complete ordinary OIDC sign-in.

Route-set format ​

Routes are ordinary option values containing versioned JSON. Version must currently be 1. Route names must be non-empty and unique. A route must contain at least one requirement. Requirements in the same route are combined with AND; separate routes are alternatives combined with OR.

json
{
  "Version": 1,
  "Routes": [
    {
      "Name": "TwoIndependentProofs",
      "Requirements": [
        {
          "TrustClass": "SavedCode",
          "Count": 1,
          "RequiredApprovals": 0,
          "ProviderCapability": null
        },
        {
          "TrustClass": "VerifiedAddress",
          "Count": 1,
          "RequiredApprovals": 0,
          "ProviderCapability": null
        }
      ]
    },
    {
      "Name": "QualifiedIdentityReproofing",
      "Requirements": [
        {
          "TrustClass": "IdentityProofing",
          "Count": 1,
          "RequiredApprovals": 0,
          "ProviderCapability": "qualified"
        }
      ]
    }
  ]
}

Recovery trust classes ​

Trust classMeaningAdditional fields
VerifiedAddressA proof delivered to a verified, non-revoked security contact.Count is 1–10.
SavedCodeA saved, single-use primary recovery code.Count is 1–10.
BoundAuthenticatorProof from an existing usable primary authenticator.Count is 1–10.
TemporaryAccessPassA reason-bound, operator-issued TAP.RequiredApprovals must be 1–10; the requester cannot approve their own operation.
IdentityProofingSuccessful asynchronous proofing by a registered provider.ProviderCapability identifies the required non-customer-defined capability, such as qualified.

Do not repeat the same trust class within one route; increase Count instead. A configured identity-proofing capability is operational only when exactly one registered provider supplies it.

Maker-checker approvals ​

OptionValues and defaultPurpose and guidance
PasskeyHighImpactApprovalPolicyJSON map; default {}Number of independent approvals required for each high-impact operation. Values are 0–10. The exact command and concurrency state are captured when approval is requested and revalidated before execution.

Supported operation keys are:

  • TemporaryAccessPassIssue
  • PolicyWeakening
  • DestructivePasswordActivation
  • RpMigrationRetirement
  • TrustOverlayChange
  • DestructiveRecommendationApply

Example:

json
{
  "TemporaryAccessPassIssue": 2,
  "PolicyWeakening": 2,
  "DestructivePasswordActivation": 2,
  "RpMigrationRetirement": 2,
  "TrustOverlayChange": 2,
  "DestructiveRecommendationApply": 2
}

The requester cannot approve their own request. Approval of one command cannot authorize a changed command, changed option concurrency state, or different operation.

Cross-option validation ​

The policy resolver rejects invalid combinations before apply. Important rules include:

  • PasskeyRequiredCredentialCount cannot exceed PasskeyMaxCredentialsPerUser or 10.
  • RemoveWhenReady and Prohibited require an operational recovery route, at least one verified security contact, and required durable notifications.
  • Required enrollment combined with Prohibited passwords requires an initial-enrollment route.
  • An attestation trust policy other than None cannot use attestation conveyance none.
  • AaguidAllowList requires at least one allowed AAGUID.
  • Allowed and blocked AAGUID sets cannot overlap.
  • The algorithm list must contain at least one server-supported safe algorithm.
  • TAP route requirements must request at least one approval.
  • Route names must be unique, requirements cannot be empty, and duplicate trust classes in one route are rejected.

Validation is necessary but does not prove operational readiness. The server can accept a syntactically valid provider-backed route even though the provider later becomes unavailable; runtime readiness reports whether the route is currently operational.

Legacy compatibility options ​

Do not add these options to a new policy. They remain readable so an upgrade preserves existing behavior until replacement options are deliberately configured.

Legacy optionCompatibility behaviorReplacement
PasskeyConditionalUiEnabledDetermines ConditionalAndButton versus Button only while PasskeyLoginExperience is absent.PasskeyLoginExperience
PasskeyEnforcePasswordlessPreserves legacy forced-passkey login only while PasskeyPasswordPolicy is absent. It is not interpreted as permission to remove a password hash.PasskeyPasswordPolicy and enrollment policy
PasskeyAllowLoginWithoutUserVerificationPreserves legacy non-UV assertion behavior only while PasskeyUserVerificationPolicy is absent.PasskeyUserVerificationPolicy
Per-user PasskeyRequirePasskeyLogin profile valueRemains compatibility-read-only and appears in migration impact. It is never automatically converted into password removal.IDP policy plus user authentication state

New-option presence wins over the corresponding legacy input. Removing a replacement option can therefore expose an older stored compatibility value; always preview removals.

Recommendation ownership ​

The four recommendations currently own and overwrite the complete replacement option set documented on this page. Applying a recommendation does not create PasskeyPolicyProfile and does not prevent later edits.

Use recommendation list/get APIs as the authoritative source for exact versioned values. The effective-policy endpoint is the authoritative source for the current resolved result.