Passkeys and MFA with Keycloak: going passwordless in your customer portal
Passkeys replace the password with a phishing-resistant login via fingerprint or PIN — and Keycloak has supported them officially since version 26.4. This article shows you as a decision-maker how passkeys work, which MFA options Keycloak ships with (OTP, WebAuthn, recovery codes), which tiered model makes sense per user group, and where rollouts stall in practice: fallback, device changes, acceptance.

Matthias Radscheit