Docs · Account

How to set up 2FA and passkeys

Verify a phone for SMS, register a passkey on the web dashboard, and store recovery codes.

EyeOut does not let a password alone open the dashboard. After password, you complete a second factor.

Phone (SMS)

On first login, add a number in E.164 form (for example +1…) and enter the SMS code. That number is used for:

  • First-time web enroll (before a passkey exists)
  • Mobile app login
  • Fallback if you have no passkeys yet

Keep the number current in Settings → Security (or your user profile). If the number is wrong, you will not get codes.

Passkeys (web)

When at least one passkey is registered, web login asks for the passkey instead of SMS.

  1. Sign in (SMS the first time).
  2. Open Security.
  3. Register a passkey on this computer (or a hardware key).
  4. Download or print the recovery codes and store them offline.

Passkeys are bound to the EyeOut site (eyeout.ca). Use https://app.eyeout.ca — not a random localhost — when you enroll a key you want in production.

You cannot remove your last passkey yourself. An org admin (tenant) or EyeOut ops (operators) can reset passkeys if you are locked out.

Recovery codes

Each code works once. They are the supported way back in if the laptop or key is gone. EyeOut cannot look up the codes later.

Related

All docs