Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

Passkeys in B2B: the real risk is recovery

Blog post from WorkOS

Post Details
Company
Date Published
Author
Zack Proser
Word Count
1,389
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

Passkeys use WebAuthn’s cryptographic origin binding to prevent phishing and eliminate shared passwords, but enterprise deployments require governance decisions that consumer-focused advice often overlooks. Synced passkeys can place corporate credentials in employees’ personal cloud accounts, limiting company visibility and revocation, while device-bound passkeys avoid that issue but make device loss and account recovery critical operational challenges. The central security question in B2B environments is who can approve a replacement passkey, since weak enrollment or recovery processes can bypass otherwise phishing-resistant login methods through social engineering or help-desk attacks. AuthKit addresses these concerns through progressive enrollment for existing users, mandatory biometric or PIN verification, support for passkeys as MFA factors, multiple passkeys per user, and stronger recovery options such as in-person verification or pre-generated recovery codes. Organizations should also establish custom domains before production enrollment because passkeys are bound to their original domain, and they should test recovery scenarios as carefully as login flows.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.