Lose a device, keep your account
Enrol a spare passkey, then retire one — the lifecycle a lost device forces on you.
- 1
On your account page, register a second passkey with its own nickname.
Nothing stops you enrolling more than one credential — `excludeCredentials` only blocks re-registering the SAME authenticator, not a genuinely different one. Real people carry a phone and a laptop.
- 2
Delete one of your passkeys, as if that device were lost or stolen.
Deletion is immediate and scoped to your account — the row (and the public key it held) is gone, so a found-then-plugged-in device can no longer authenticate as you.
- 3
If you ever delete your LAST passkey, log out and use “Forgot access”.
Recovery re-proves your mailbox with a one-time code — the same trust anchor signup used — and lets you enroll a fresh passkey. Losing a device is recoverable; losing your email is the one thing you can’t.
Do it
This one happens on your account page — register a passkey, revoke a session, or enroll TOTP there.
Go to your account →🩻 X-ray — what actually happened
Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.