Skip to main content

Security setup

Two-factor authentication (2FA) adds a second verification step when signing in to Passwork. Even if your password is compromised, an attacker cannot access your account without the second factor.

tip

Your administrator may not enforce 2FA as a mandatory policy. To ensure proper security, set it up immediately after activating your account rather than wait for it to become mandatory.

Open the 2FA settings

  1. Click your profile icon or Settings and users at the top of Passwork interface.
  2. Open the Authentication page.
  3. Scroll to the Two-factor authentication (2FA) section.

To make changes, click the lock icon in the top-right corner of the page to unlock it for editing.

Two-factor authentication section in account settings

Connect a TOTP authenticator app

Use the Passwork 2FA app or any third-party app that supports TOTP (Time-based One-Time Passwords), such as Google Authenticator or Microsoft Authenticator.

  1. In the Passwork 2FA and TOTP section, click Connect.
2FA Connect button
  1. And choose the 2FA method you want to use.
2FA method selection

Passwork 2FA app

If your Passwork server is connected to the Internet and you wish to log into Passwork in one tap, choose the Passwork 2FA option and scan the QR code using the app.

If the application is not yet installed on your mobile device, you can get it from App Store or Google Play

Passwork 2FA app — scan QR code

Third-party TOTP app (Google Authenticator, Microsoft Authenticator, etc.)

Select One-time password, then scan the QR code using your authenticator app. Enter the 6-digit code shown in the app to confirm the connection.

TOTP setup — QR code scan

Connect a hardware security key or biometrics

Passwork supports WebAuthn-compatible devices, including physical security keys (YubiKey, FIDO2) and biometric authentication (fingerprint, Face ID).

In the Biometrics and security keys section, click Add and follow the on-screen instructions.

Adding a security key or biometric factor

Managing your 2FA connection

After 2FA is set up, you can:

  • Enable or disable 2FA temporarily (if your organization's policy allows it)
  • Remove the connected method and replace it with a new one
  • Set up a new connection
2FA management panel

For full 2FA documentation, see Two-factor authentication.


Passkeys — passwordless sign-in

In addition to 2FA, Passwork supports passkeys: a modern, phishing-resistant authentication method that replaces the password entirely. A passkey uses your device's biometrics (Face ID, Touch ID, Windows Hello) or a physical security key (YubiKey, FIDO2) to verify your identity.

info

Passkeys as a sign-in method must be enabled by your administrator in your role settings. If you do not see the option below, contact your IT administrator.

Add a passkey

  1. Go to Account settings → Authentication.
  2. Click the lock icon to unlock the page for editing.
  3. In the Passkey section, click Add.
Add passkey button in Authentication settings
  1. Follow the system prompt to register your device's biometric sensor or physical security key.

Once added, you can sign in to Passwork by clicking Sign in with passkey on the login page — no password required.

Manage passkeys

You can add multiple passkeys — for example, one on your laptop and one on a physical security key stored securely. If you lose access to one, you can sign in with another without needing an administrator reset.

Passkey management — rename and delete

For full documentation, see Sign-in methods.

Next step

Proceed to Basic operations to save your first password and use autofill.