Migrate from Two Factor
Migrate from Two Factor
Last verified: 2026-06-11
This is a checklist, not an importer. It helps you move deliberately while keeping a recovery path.
The Two Factor plugin focuses on administrator two-factor methods. If your current setup uses a separate WebAuthn provider plugin, passkey behavior may need to be re-created in Awthy rather than moved automatically.
Before you start
- Confirm at least one administrator can sign in.
- Save current recovery codes or emergency access instructions from the existing plugin.
- Install Awthy without disabling the existing plugin.
- Set up Awthy two-factor authentication and recovery codes for one administrator.
Do not remove the old plugin until at least one administrator has tested Awthy sign-in and recovery.
Migration checklist
- Verify Awthy sign-in for one administrator.
- Verify recovery codes before enforcing a policy.
- Decide whether customers are optional, invited, or excluded for now.
- Disable the old plugin only after Awthy sign-in and recovery are tested.
What does not migrate automatically
- Existing authenticator-app secrets.
- Existing passkeys or WebAuthn credentials.
- Existing recovery codes.
- Existing trusted-device cookies.
Rollback
If sign-in fails, use the old plugin's documented recovery path or Awthy recovery codes before changing enforcement settings.