Skip to main content

Trusted Devices

Trusted Devices

Last verified: 2026-07-08

Trusted devices let Awthy remember a browser after a successful second-factor challenge so the same browser can skip repeated prompts for a limited time. They are a convenience feature, not a replacement for strong account recovery or device security.

Creating trust

When trusted devices are allowed, the login challenge can show Trust this device for 30 days. Awthy creates the trusted-device record only after the user completes the second-factor challenge successfully.

Use trusted devices on private devices you control. Do not use them on shared computers, public terminals, borrowed devices, unmanaged staff devices, or browsers where other people can access the profile.

What trust bypasses

A trusted device can bypass the second-factor prompt for the remembered browser while the trust record remains valid. It does not bypass the WordPress password, role policy, account status, incident lockdown, IP access rules, or other site-level controls.

If a site changes security policy, a previously trusted browser may still need to pass a stronger challenge.

Revoking trust

Open Account Security and use the Trusted devices panel to remove one remembered browser or all trusted devices for the account. Revocation is appropriate when a device is lost, sold, shared, compromised, or simply no longer used.

Admins should include trusted-device cleanup in staff offboarding and incident response.

Admin and customer differences

Administrators and shop staff should use trusted devices sparingly because their accounts can change site behavior and customer data. Customer trusted devices can reduce friction for repeat purchasers, but they still require clear recovery and support guidance before broad rollout.

Paid-plan availability can affect which audiences may use trusted-device convenience.

Shared-device cautions

If more than one person uses the same operating-system account or browser profile, do not trust that device. A trusted browser depends on local browser storage and cookies. Anyone with access to that profile can benefit from the remembered trust until it expires or is revoked.

Data boundaries

Trusted-device tokens are stored as one-way hashes. Awthy does not store a raw trusted-device token in the database and does not expose raw cookies in the UI, audit log, or support reports.