After Passkeys are enabled, users can manage the credentials attached to their WordPress account from supported VentraConnect profile or account experiences.
Add Another Passkey
Adding more than one Passkey is useful when a user signs in from multiple devices or wants a backup authenticator.
Sign in to the WordPress account
Open the supported profile or account area where VentraConnect Passkeys are managed.
Select Add Passkey
The browser starts a new WebAuthn credential-registration request.
Choose a different device or authenticator if needed
Users can register another compatible authenticator instead of relying on only one device.
Complete verification
After successful browser verification, the new credential is attached to the same WordPress account.
Remove a Passkey
Users should remove credentials they no longer control, such as credentials created on an old or replaced device.
Before removing the last Passkey: make sure the account still has another working login method available unless your site deliberately requires a different recovery process.
Using Multiple Devices
A Passkey may be tied to a specific device, synchronized by an operating-system or password-manager ecosystem, or stored on a hardware authenticator. The exact behavior depends on the user’s environment.
- Device-bound experience: the user may need to register a Passkey separately on another computer or security key.
- Synced Passkey experience: some platforms and password managers can make an existing Passkey available on other signed-in devices.
- Cross-device sign-in: some browsers can offer a phone or nearby device as the authenticator for a login attempt.
Recovery and Fallback
Passkeys should be part of a deliberate account-recovery strategy, especially while users are still adopting them.
- Keep Social Login, Magic Link, Email OTP, or password login available when appropriate for your site.
- Encourage users with important accounts to register more than one Passkey where practical.
- Use Pro Password Phaseout carefully; do not move to stricter behavior until users have a safe alternative to passwords.
- For administrators, preserve an emergency-access path when using Password Phaseout.
Existing Users vs New Users
For an existing user, a Passkey is added to that user’s existing WordPress account. Passkey registration should not be treated as a reason to create a duplicate account.
For new-user registration flows, VentraConnect uses the supported registration path and account rules configured for the site before the Passkey can become a credential for that new WordPress account.
Security Notes
- Removing a Passkey from WordPress prevents that credential from authenticating through that VentraConnect account record.
- The user’s biometric template is not stored by VentraConnect.
- The private Passkey credential remains protected by the user’s authenticator.
- Users should remove credentials they no longer control.