Passkeys ship with two modes out of the box:
→ Primary auth — passwordless sign-in with Face ID, Touch ID, or a hardware key
→ 2FA layer — passkey prompt after password login, replacing TOTP
One config flag to enable. Up to 5 passkeys per user. Cloned authenticator detection included.