BetterShield
Two-factorPasskeysSign-in

WordPress two-factor authentication and passkeys: a setup guide

BetterShield team · · 9 min read

A password is one secret, and one secret can be guessed, reused from someone else’s breach or typed into a convincing copy of your sign-in page. WordPress two-factor authentication adds a second step: after the password, a six-digit code from an app on your phone. A stolen password alone stops being enough.

Passkeys go further. You sign in with your fingerprint, your face or your device PIN, and there is nothing to type.

BetterShield 1.1.0 includes both in the free plugin. This guide sets them up for your account, then for your team and customers, and covers the day someone loses their phone.

Quick summary

  • WordPress 2FA in BetterShield works with any authenticator app and comes with 10 single-use backup codes. It turns on only at the last step.
  • Require two-factor of a role gives a grace period, 14 days by default, and is enforced in the dashboard, never at the sign-in page.
  • Passkeys sign you in with a fingerprint, face or device PIN. Each account can hold up to 10, and the site needs HTTPS.
  • Sign in with a passkey only stops a password working once an account holds a passkey, and only after a way back in is ready.
  • WooCommerce customers manage both on My Account › Sign-in security.

What two-factor and passkeys add

Two-factor asks for something you have as well as something you know. After your password, an Authentication code screen asks for the code your authenticator app shows, which changes every thirty seconds.

A passkey is a key your device keeps and unlocks with your fingerprint, face or PIN. The key never leaves that device, and your site stores only the public half. Your browser offers it only to the exact address it was made for, so a fake copy of your sign-in page cannot get it out of you the way it could a password.

Application passwords for connected tools keep working with both, because each one is already its own second factor.

Set up WordPress two-factor authentication for your account

Administrators open BetterShield › Protect › Two-Factor and use the Two-factor authentication card:

  1. Press Set up two-factor.
  2. Open any authenticator app that makes six-digit codes, such as 1Password, Google Authenticator, Microsoft Authenticator, Authy or Bitwarden.
  3. Scan the QR code, or type the Manual entry key into the app.
  4. Enter the code the app shows and press Confirm code. Cancel discards the setup.
  5. Store your ten backup codes with Copy codes or Download as a file. They are shown only once, and each works once.
  6. Press I have stored these codes to turn two-factor on.

Until step 6, signing in works exactly as before.

Afterwards, the card shows how many backup codes are unused. Under New backup codes, enter an App code or backup code and press Issue new codes; the new set replaces every old code. Turn off asks for a current code too, so nobody at an unlocked screen can quietly remove it.

Everyone else uses Two-factor sign-in on their own Profile screen, with the same steps. Quick Setup also offers Set up two-factor for your account.

Require two-factor by role

Under What the site requires, the Require two-factor of a role panel asks the roles you tick to set it up:

  1. Tick the roles, such as Administrator and Editor.
  2. Set Grace period, in days, from 0 to 90. The default is 14, and zero asks immediately.
  3. Press Save requirement.

Before a role is added, BetterShield checks that you have a working recovery link or printed recovery codes, as it does before a sign-in hardening fix. The Locked out guide explains both.

How enforcement works:

  • The clock starts when an account first meets the requirement, not when it was created, so long-standing accounts get the full window.
  • During the grace period, people see a countdown on every dashboard page, with a Set it up now link.
  • After it, the dashboard takes them to the setup screen until they finish. Their profile screen and signing out keep working.
  • Sign-in is never blocked. The requirement is enforced inside the dashboard, after the password, and safe mode stands it down.

Add WordPress passkeys for passwordless sign-in

On the Passkeys card, on Protect › Two-Factor or your Profile screen, type a name in Name this device, press Add a passkey, and confirm with your fingerprint, face or PIN.

A passkey is an extra way in: your password, backup codes and recovery link keep working. Add one on each device you use, up to 10 per account. Each shows when it was last used, and Remove deletes it after you confirm. Passkeys need HTTPS; without it, the card says why.

Once any account has a passkey, the WordPress sign-in page (wp-login.php) shows Sign in with a passkey below the Log In button. Press it and confirm on your device: passwordless login for WordPress, with nothing to type.

How a passkey counts depends on how your device unlocks it:

  • With a fingerprint, face or PIN, it counts as both factors, so no code is asked.
  • With only a touch, it proves you hold the key, not who you are. A two-factor account still asks for the app code, and on its own the key is not accepted.

Passkey-only sign-in by role

Sign in with a passkey only goes further. For the roles you tick, an account’s password stops signing it in once that account has added a passkey. A password that cannot sign anyone in cannot be phished, guessed or reused from a breach. A line per role shows how many of its accounts have a passkey, and Save requirement applies it.

Its safeguards:

  • Nobody is refused until they hold a passkey. Everyone else keeps their password and is asked on their dashboard, so there is no deadline to count down.
  • A way back in comes first. Adding a role is refused unless the site has a working recovery link or printed recovery codes (Protect › Recovery), and passkeys work on the site.
  • A refused password explains itself. The message points to the Sign in with a passkey button. XML-RPC needs an application password instead.
  • A lost passkey has a way back. The recovery link, a printed recovery code, or removing the last passkey brings password sign-in back.

WooCommerce customers

Customers manage their own sign-in on My Account › Sign-in security: the same two-factor and passkey panels as the profile screen, plus where they are signed in. BetterShield adds nothing to the cart or checkout.

Require two-factor of a role is asked for in the dashboard, and WooCommerce sends customers to My Account instead, so it does not ask them. They can still set it up themselves. Under Sign in with a passkey only, a customer with a passkey signs in on the site’s own sign-in page (wp-login.php), the only page with the passkey button.

When someone loses their device

  1. A backup code. On the Authentication code screen, an unused backup code works in place of the app code. Once in, another unused code under Turn off lets them set two-factor up again on the new phone.
  2. No codes left. An administrator opens Users, edits the account, and under Two-factor sign-in presses Turn off two-factor for this account. The person signs in with their password and sets it up again.
  3. A passkey-only account. An administrator can untick its role under Sign in with a passkey only, which brings password sign-in back for that role. A role the network requires cannot be unticked on one site.

If you are the one locked out, your recovery link or a printed recovery code gets you into the dashboard. Locked out of WordPress? walks through each case.

Multisite networks in brief

On BetterShield › Network, Require two-factor across the network (with its own Grace period, in days) and Passkey-only roles across the network set a floor for every site. Both start as Not set. A site can add roles but not remove the network’s, and the shorter grace period applies. Adding a passkey-only role needs a working recovery link or printed codes on every site. See the Multisite networks guide.

Common mistakes

  • Pressing the last button before storing the codes. The ten backup codes are shown once. Keep them where you keep passwords.
  • Guessing at codes. After ten wrong codes in an hour, that account’s codes are not checked for a while, and wrong codes count toward a sign-in lockout. Use the current code or a backup code.
  • Keeping one passkey on one device. If that device is lost, so is that way in. Add a second.
  • Running two-factor in two plugins. People can end up asked twice. If another security plugin is active, Quick Setup asks which one keeps two-factor.

Frequently asked questions

Can two-factor authentication lock my users out?

Not by setting it up. Nothing is enforced until the app is proven to work and the codes are stored, and a required role gets a grace period. A lost phone is covered by a backup code, or an administrator turning two-factor off.

Does a passkey replace two-factor?

It can cover both steps. A passkey unlocked with a fingerprint, face or PIN counts as both factors, so no code is asked. One that only asks for a touch still needs the app code on a two-factor account.

Will two-factor break tools connected to my site?

Application passwords keep working as they are. A tool that signs in over XML-RPC with the account password is refused once that account uses two-factor, and needs an application password instead.

Do passkeys work on every site and browser?

They need HTTPS. Current versions of Chrome, Safari, Edge and Firefox can all use them, and the Passkeys card tells you when a browser cannot.

Is WordPress 2FA free in BetterShield?

Yes. Two-factor, backup codes, passkeys, required two-factor and passkey-only sign-in are all in the free BetterShield plugin on WordPress.org, with no account needed.

Conclusion

Start with your own account: set up two-factor, store the ten codes, and add a passkey on the device you use most. Then tick the roles that should need it and give them the default 14 days.

The option-by-option reference is the Two-factor and passkeys guide, and Support is there if you get stuck.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield