Skip to content

Two-Factor Authentication (2FA) & WebAuthn Passkeys

Pocket Kit provides enterprise-grade multi-factor security for your account. You can protect your deployments and database instances using standard Authenticator apps or hardware biometrics.

Authentication Methods

Pocket Kit supports three multi-factor authentication methods:

  1. RFC 6238 Time-based One-Time Passwords (TOTP): Compatible with Google Authenticator, 1Password, Authy, Apple Keychain, and Bitwarden.
  2. FIDO2 / WebAuthn Biometric Passkeys: Hardware-backed credentials using Apple Touch ID / Face ID, Windows Hello, Android Biometrics, and physical YubiKeys.
  3. Emergency Backup Recovery Codes: 8 cryptographically unique 8-character emergency codes for account recovery if you lose access to your primary 2FA device.

Setting Up Google Authenticator (TOTP)

  1. Open the Settings view in your Pocket Kit console.
  2. Navigate to the Two-Factor Authentication (2FA) section.
  3. Click “Enable 2FA”.
  4. Scan the rendered QR code with your mobile authenticator app (e.g., Google Authenticator, 1Password).
  5. Enter the 6-digit confirmation code displayed on your device.
  6. Copy and save your 8 Emergency Recovery Codes in a safe place.

Setting Up WebAuthn Passkeys

  1. In the Settings view under WebAuthn Passkeys & Hardware Keys, click “Register New Passkey”.
  2. Give your passkey a recognizable name (e.g. MacBook Pro Touch ID, YubiKey 5C).
  3. Follow your browser prompt to tap your fingerprint reader or touch your security key.
  4. The passkey is instantly registered and can be used on subsequent logins.

Login Flow with 2FA Enabled

When logging into Pocket Kit:

  1. Enter your email and password as normal.
  2. If 2FA is active on your account, Pocket Kit issues a temporary 5-minute encrypted challenge token and presents the MFA verification modal.
  3. You can authenticate using:
    • Your 6-digit TOTP code from your authenticator app
    • Your WebAuthn biometric passkey
    • An unused Emergency Recovery Backup Code