Two-Factor Authentication (2FA) & WebAuthn Passkeys
Pocket Kit provides enterprise-grade multi-factor security for your account. You can protect your deployments and database instances using standard Authenticator apps or hardware biometrics.
Authentication Methods
Pocket Kit supports three multi-factor authentication methods:
- RFC 6238 Time-based One-Time Passwords (TOTP): Compatible with Google Authenticator, 1Password, Authy, Apple Keychain, and Bitwarden.
- FIDO2 / WebAuthn Biometric Passkeys: Hardware-backed credentials using Apple Touch ID / Face ID, Windows Hello, Android Biometrics, and physical YubiKeys.
- Emergency Backup Recovery Codes: 8 cryptographically unique 8-character emergency codes for account recovery if you lose access to your primary 2FA device.
Setting Up Google Authenticator (TOTP)
- Open the Settings view in your Pocket Kit console.
- Navigate to the Two-Factor Authentication (2FA) section.
- Click “Enable 2FA”.
- Scan the rendered QR code with your mobile authenticator app (e.g., Google Authenticator, 1Password).
- Enter the 6-digit confirmation code displayed on your device.
- Copy and save your 8 Emergency Recovery Codes in a safe place.
Setting Up WebAuthn Passkeys
- In the Settings view under WebAuthn Passkeys & Hardware Keys, click “Register New Passkey”.
- Give your passkey a recognizable name (e.g.
MacBook Pro Touch ID,YubiKey 5C). - Follow your browser prompt to tap your fingerprint reader or touch your security key.
- The passkey is instantly registered and can be used on subsequent logins.
Login Flow with 2FA Enabled
When logging into Pocket Kit:
- Enter your email and password as normal.
- If 2FA is active on your account, Pocket Kit issues a temporary 5-minute encrypted challenge token and presents the MFA verification modal.
- You can authenticate using:
- Your 6-digit TOTP code from your authenticator app
- Your WebAuthn biometric passkey
- An unused Emergency Recovery Backup Code