signup: make passkey the primary choice, and name the cost of the password path #166

Öppen
öppnade 2026-08-02 12:30:27 +00:00 av supernaut · 0 kommentarer
Ägare

Why

Every person is already required to hold MFA — the identity provider's account policy on
idm_all_persons sets credential_type_minimum = mfa. A passkey ranks above mfa and satisfies
that policy on its own
, so a passkey user never sees a second-factor prompt. A password user must
additionally enrol TOTP, which means installing an authenticator app.

Both branches are presented today as an even choice. The sign-up step reads "choose how you sign
in — set a passkey or password", and the FAQ opens with "No, a password works too." A user picking
"password" is therefore opting into the authenticator-app path without being told so, which is the
single largest avoidable source of onboarding friction we have.

Platform authenticators (Face ID, Touch ID, Windows Hello, Android biometrics) are less work than
a password: nothing to install, nothing to transcribe, no clock skew, and they cannot be phished.
Upstream calls passkeys "the preferred method of authentication" and has been retiring the
alternatives — security keys as a second factor were deprecated for removal, with the note that
"Security Keys are surpassed by PassKeys which give a better user experience".

Scope

  • Sign-up / credential-setup copy: passkey is the visually primary action; password is the
    secondary one.
  • State the consequence on the password path, in plain language: choosing a password also means
    setting up an authenticator app.
  • Update the FAQ entry "Do I have to use a passkey?" so the trade-off is explicit rather than
    neutral.
  • Run the content style guide over the new copy (EN + SV).

Explicitly out of scope

Do not raise credential_type_minimum to passkey. There is no
reset-credential-type-minimum, downgrades are restricted, and it would lock out every
password-only person including break-glass, with no way back. This issue is about steering, not
enforcement.

Done when

Sign-up and the FAQ both make passkey the default reading, the password path names its own cost,
and both languages pass the style check.

Part of gitborg/gitborg-docs#69.

## Why Every person is already required to hold MFA — the identity provider's account policy on `idm_all_persons` sets `credential_type_minimum = mfa`. A **passkey ranks above `mfa` and satisfies that policy on its own**, so a passkey user never sees a second-factor prompt. A password user must additionally enrol TOTP, which means installing an authenticator app. Both branches are presented today as an even choice. The sign-up step reads "choose how you sign in — set a passkey or password", and the FAQ opens with "No, a password works too." A user picking "password" is therefore opting into the authenticator-app path without being told so, which is the single largest avoidable source of onboarding friction we have. Platform authenticators (Face ID, Touch ID, Windows Hello, Android biometrics) are *less* work than a password: nothing to install, nothing to transcribe, no clock skew, and they cannot be phished. Upstream calls passkeys "the preferred method of authentication" and has been retiring the alternatives — security keys as a second factor were deprecated for removal, with the note that "Security Keys are surpassed by PassKeys which give a better user experience". ## Scope - Sign-up / credential-setup copy: passkey is the visually primary action; password is the secondary one. - State the consequence on the password path, in plain language: choosing a password also means setting up an authenticator app. - Update the FAQ entry "Do I have to use a passkey?" so the trade-off is explicit rather than neutral. - Run the content style guide over the new copy (EN + SV). ## Explicitly out of scope **Do not** raise `credential_type_minimum` to `passkey`. There is no `reset-credential-type-minimum`, downgrades are restricted, and it would lock out every password-only person including break-glass, with no way back. This issue is about steering, not enforcement. ## Done when Sign-up and the FAQ both make passkey the default reading, the password path names its own cost, and both languages pass the style check. Part of gitborg/gitborg-docs#69.
supernaut lade till detta till projektet Bitborg Web 2026-08-02 12:34:31 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web#166
Ingen beskrivning angiven.