Account security: MFA and passkeys for Simbase accounts

This section covers how to protect access to your Simbase account itself: who can sign in, and what they have to prove before the dashboard lets them through. If you're looking for SIM-level protection (locking a SIM to a specific device so a stolen card stops working), that's Theft Protection in the Dashboard section.

There are two methods to harden your sign-in, and they work together rather than against each other: multi-factor authentication (MFA) and passkeys. Both are per-user, both take about a minute to set up, and both stop the most common ways accounts get compromised.

How to use this section

If you've never set anything up beyond your password, read the recommended setup below first and then follow the two articles in order. If you already have MFA running and want to move to something faster and phishing-resistant, jump straight to passkeys. Each article is self-contained, so you can land on either one without reading the other.

What's in here

  • Multi-factor authentication (MFA), add a six-digit authenticator code on top of your password. Works with any TOTP app: Google Authenticator, 1Password, Authy, Microsoft Authenticator, Bitwarden.

  • Passkeys, sign in with your device's fingerprint, face, or PIN instead of a password. Phishing-resistant, and a successful passkey sign-in counts as both factors so MFA isn't prompted on top.

For most accounts, layer the methods rather than picking one:

  1. Set up a passkey on your primary device (laptop or phone) for everyday sign-in. This is the fastest path in and the hardest to phish.

  2. Add a second passkey on a different device as a backup. If you lose or replace one device, you can still get in with the other.

  3. Keep your password and MFA enabled as a final fallback. Don't strip them out unless you have multiple passkeys you trust.

The result is layered: passkey for daily use, MFA as a backup when you sign in from somewhere new, and the password as the final safety net.

Which method does what

Behaviour
  • What you provide

  • Phishing-resistant?

  • Counts as multi-factor on its own?

  • Needs your phone?

  • Recovery if you lose the device

Can I have both?Both can be enabled at the same time. They're complementary.

Looking for something else?