L IntegrAuth Lab

← All practicals

P17

Lose a device, keep your account

Enrol a spare passkey, then retire one — the lifecycle a lost device forces on you.

  1. 1

    On your account page, register a second passkey with its own nickname.

    Nothing stops you enrolling more than one credential — `excludeCredentials` only blocks re-registering the SAME authenticator, not a genuinely different one. Real people carry a phone and a laptop.

  2. 2

    Delete one of your passkeys, as if that device were lost or stolen.

    Deletion is immediate and scoped to your account — the row (and the public key it held) is gone, so a found-then-plugged-in device can no longer authenticate as you.

  3. 3

    If you ever delete your LAST passkey, log out and use “Forgot access”.

    Recovery re-proves your mailbox with a one-time code — the same trust anchor signup used — and lets you enroll a fresh passkey. Losing a device is recoverable; losing your email is the one thing you can’t.

Do it

This one happens on your account page — register a passkey, revoke a session, or enroll TOTP there.

Go to your account →

🩻 X-ray — what actually happened

Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.