Step-up verification

Ask a user for a second proof after their password: a passkey, or a code from an authenticator app. You can require it before a sensitive operation, or on every sign-in to an app.

A second step, after a password

A passkey here is a second factor and never a way to sign in on its own: the sign-in page offers no passkey option. A security key can be used in its place. Stepping up re-checks the password first, so only a user who has a password can enrol a factor or prove one.

Before a sensitive operation

An operation can require a second factor. You set the requirement with foir operations update and its --second-factor flag, and it reaches production at the next release. A run whose session has not proven a factor is refused with FAILED_PRECONDITION and a message you can word yourself. An operation that carries the requirement cannot be started by a hook or a schedule.

On every sign-in to an app

Each sign-in app has a Require MFA switch in the console. With it on, a password sign-in on the hosted page completes only after the user proves a factor. A user with none enrols during that sign-in, with a passkey or by scanning a QR code into an authenticator app.

The switch also shuts out anyone without a password. Users who sign in with an emailed code or through an identity provider cannot sign in to that app at all.

Stepping up without signing out

A signed-in user can enrol or step up in the middle of a session. They re-enter their password and prove the factor, and the proof is added to the session they already hold. This needs a session on a verified custom login domain. An app on the token flow has no such session, and its users get a second factor by signing in again through an app that requires one.

Read the detail

Step-up has no documentation page of its own, and the operation endpoint guide covers only the requirement you set on an operation.