What is the "Password + Passkey" method for authentication?

Vincent Delitz

Vincent

Created: January 8, 2025

Updated: April 25, 2025

passkeys product design strategy

Read the full article

Read the enterprise guide on large-scale passkey integration approaches, design of user flows and interfaces, and technical implementation considerations.

Read the full article

Already read by 5,000+ enterprise security leaders.


What is the "Password + Passkey" Method for Authentication?#

The "Password + Passkey" method combines traditional password-based login with passkeys as a second authentication factor, providing enhanced security while supporting a gradual transition to passkey adoption.

password passkey authentication

User Experience#

  1. The user begins by entering their password as usual.
  2. After successful password entry:
    • If a passkey is available, the user is prompted to authenticate using biometrics (e.g., fingerprint or face recognition) or a PIN.
    • If no passkey is available, the user falls back to other MFA methods, such as SMS OTPs.
  3. Users are encouraged to create a passkey during this process to streamline future logins.

Benefits#

Enterprise Icon

Get free passkey whitepaper for enterprises.

Get for free

Challenges#

  • Increased Steps: Users must first enter a password before using a passkey, which may introduce friction.
  • Limited Passkey Functionality: Advanced passkey features like One-Tap Login or Conditional UI cannot be fully utilized when passwords are required.

Real-World Example#

Amazon implements this method, requiring a passkey as an additional step after password entry to enhance security while maintaining compatibility with existing systems.

This approach is ideal for organizations seeking a secure, stepwise integration of passkeys while maintaining familiarity for users accustomed to passwords.

Read the full article#

passkeys product design strategy

Read the full article

Read the enterprise guide on large-scale passkey integration approaches, design of user flows and interfaces, and technical implementation considerations.

Read the full article

Already read by 5,000+ enterprise security leaders.

Add passkeys to your app in <1 hour with our UI components, SDKs & guides.

Start for free

Enjoyed this read?

🤝 Join our Passkeys Community

Share passkeys implementation tips and get support to free the world from passwords.

🚀 Subscribe to Substack

Get the latest news, strategies, and insights about passkeys sent straight to your inbox.

Share this article


LinkedInTwitterFacebook