Checkout & hosted pages

Securing the customer portal: passkeys and 2FA

Overview

In the customer portal your customers see their invoices, subscriptions and payment details — exactly the information nobody else should see. Kyvento offers two additional layers of security for it: passkeys (signing in with a fingerprint, face recognition or device PIN) and two-factor authentication via an app. You decide as the provider whether both are offered; your customers decide whether to use them.

What your customers can set up

  • Passkey — the customer signs in with whatever already protects their device: fingerprint, face recognition or device PIN. There is no password that could be guessed or phished. A customer can store several passkeys, for example for a laptop and a phone.
  • Two-factor authentication (2FA) — in addition to the password, the customer enters a six-digit code from an authenticator app. During setup they receive recovery codes; those are the lifeline if the phone is lost.

Customers find both in the portal under “Security”. They can enable and remove them at any time themselves.

What you configure

Under Settings → Customer portal → Security you decide what is offered in the portal at all. It makes sense to enable both and let customers choose: passkeys are more convenient, an authenticator app works on any device.

The security reset: when a customer is locked out, or an account may be compromised

There is one operation for both emergencies: the security reset. It clears the customer's portal access completely:

  • two-factor authentication is disabled,
  • all stored passkeys are deleted,
  • every signed-in device is logged out and outstanding sign-in links are invalidated.

That is deliberate, not excessive: whoever triggers the reset does so because the account may be in someone else's hands. If the passkey or an already sent sign-in link survived, the reset would invalidate everything except the very route the attacker came in through.

The customer sets everything up again afterwards — passkey and second factor are both gone, not just one of them. Tell them that up front, or they will face a portal that suddenly no longer recognises them.

How to trigger it

Not yourself, for now. Kyvento offers the security reset neither as a button in the interface nor through the public API — it is deliberately limited to the internal route. If one of your customers is locked out, or you suspect a compromised account, contact our support. We will run the reset for you.

Have ready which customer it concerns and why. And verify who you are talking to first: a reset removes every layer of protection at once — exactly the lever an outsider is looking for. A call back to the stored number is the simplest safeguard. Every reset is recorded in the audit log and can be traced later.

Good to know

  • Passkeys are tied to the device they were created on — or to the customer’s password manager, if they sync them there.
  • Recovery codes can only be used once. Anyone who has used them all should generate new ones in the portal.
  • These settings only affect the customer portal. Securing your own Kyvento access is covered in “Enabling two-factor authentication”.

Next steps

  • Secure your own access — see “Enabling two-factor authentication”
← Back to Support

Related articles

Checkout & hosted pages

Setting up hosted pages

Overview With hosted pages you sell your subscriptions without a single line of your own code: Kyvento provides a ready-...

Checkout & hosted pages

Using your own checkout domain

Overview With your own domain, your checkout runs at buy.yourcompany.com instead of a Kyvento address – and the customer...