Passkey step-up
Require recent user-verified public-key authentication.
Combine passkeys, registered-device push challenges, number matching, device posture, and policy-driven step-up. Manually entered OTP is not described as phishing-resistant.
Require recent user-verified public-key authentication.
Bind approval or denial to a registered device and challenge.
Use evaluated posture without treating self-report as attestation.
Expire challenges and refuse already-consumed proof.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Document the environment, threat model, and integration boundary.
Select protocols, signals, policies, and failure behavior.
Test vendor-specific APIs, tenant isolation, and abuse paths.
Mark available only after deployed end-to-end verification.