Skip to help content
Account and security

Secure your account with passkeys and MFA

Set up passkeys, authenticator codes, recovery codes, and step-up checks for sensitive actions.

Choose at least two recovery paths

A passkey uses your device or password manager to resist phishing. A TOTP authenticator produces a six-digit rotating code. Recovery codes are single-use backups for times when the primary factor is unavailable.

  • Register a passkey on a device or password manager you control.
  • Enable an authenticator app when you want a portable code-based factor.
  • Generate recovery codes and store them offline, separate from your password.

Complete an MFA sign-in

After the first sign-in step, Astral asks for an available second factor. Use a passkey, a current authenticator code, or one unused recovery code. A recovery code is consumed after a successful check.

Sensitive actions require a fresh check

Creating or revoking API keys, changing custom domains or billing, revoking sessions, and deleting the account can require a recent MFA step-up. Astral keeps technical API error codes stable so clients can distinguish a missing step-up from another failure.

If a factor is lost

  1. Try another registered passkey or authenticator device.
  2. Use one saved recovery code.
  3. After regaining access, remove the lost factor, register a replacement, and regenerate recovery codes.

Note: Astral cannot display an old TOTP secret or used recovery code. Do not send factors or recovery codes to support.

Related guides