Skip to main content

Login Challenge

Login Challenge

Last verified: 2026-07-08

The login challenge appears after the password stage when Awthy requires a second factor. It protects browser sign-ins and selected authentication paths according to the site's policy.

Authenticator code

Use the 6-digit code from the authenticator app linked to the account. If the code just changed, wait for the next code and try again. Repeated failures can trigger backoff so brute-force attempts slow down.

Backup code

If the authenticator device is unavailable, choose the recovery-code option and enter one unused backup code. Each backup code works once. Store unused codes outside WordPress, such as in a password manager.

Do not paste backup codes into support tickets, chat, screenshots, or email.

Passkey assertion

If the account has a registered passkey and the browser supports it, choose Use a passkey. The browser or device will show its own passkey prompt. If that prompt fails, use an authenticator code, backup code, or recovery path instead.

Email recovery

If the user cannot use a factor, the challenge can request an email recovery link. Email recovery is short-lived operational state, not a standing second factor. The account must still repair enrollment after using recovery.

Recovery links should go only to the account owner. Never forward a recovery link to support or another user.

Trusted-device checkbox

When trusted devices are allowed, the challenge can offer Trust this device for 30 days. Use it only on private devices and browser profiles controlled by the account owner. It creates trust only after a successful second-factor challenge.

Lockout and retry behavior

Awthy slows repeated failed attempts. This protects accounts from guessing attacks but can temporarily delay legitimate retries. If a user is stuck, use the support-desk recovery workflow rather than asking them to share codes or secrets.

What Awthy never asks for

Awthy will not ask a user to send a password, authenticator seed, raw passkey challenge, unused backup code, trusted-device cookie, or recovery link to support.