# Settings

The **Settings** tab allows administrators to manage global behavior, user permissions, and security parameters for WebAuthn passkey authentication across your WordPress site. To navigate, go to **Login & Authentication** → **Two Factor Authentication** → **Passkeys** → **Settings**.

![ultimate security passkey (biometric login) settings page](https://docs.wpultimatesecurity.com/wp-content/uploads/2026/02/ultimate-security-passkey-biometric-login-settings-page-1.png)

## Enable Passkeys

**What it does:** Serves as the master switch for passwordless sign-in across your site.

**How to use:** Toggle **ON** to allow users to authenticate using biometrics (Touch ID, Face ID), device PINs, or physical security keys. Toggle **OFF** to suspend passkey authentication without losing saved settings.

## Enable Maximum Passkeys

**What it does:** Controls whether users are restricted in the number of passkeys they can attach to a single account.

**How to use:** Toggle **ON** to set a registration cap per user. If disabled, users can register an unlimited number of authenticators.

## Max Passkeys Number

**What it does:** Sets the maximum count of active passkeys allowed per account when *Enable Maximum Passkeys* is active.

**How to use:** Enter your numeric limit. Once a user reaches this limit, they must delete an existing passkey before adding a new device.

## Enabled User Roles

**What it does:** Restricts passkey registration and sign-in capabilities to specific WordPress user roles.

**How to use:** Select target roles from the menu. Use **Select All** to grant access across all roles or **Remove All** to clear selections. Unselected roles will not see passkey setup options in their profile or shortcode forms.

## **Exclude Existing Credentials**

**What it does:** Prevents users from registering the exact same physical device or authenticator multiple times on one account.

**How to use:** Keep this toggled **ON** to maintain clean records and prevent duplicate entry errors during authentication.

## **Registration Timeout**

**What it does:** Sets the maximum time allowed for a user to complete biometric or device verification during the registration process.

**How to use:** Enter the duration in minutes. If the user does not authorize their device within this window, the registration process automatically cancels.

## **Login Timeout**

**What it does:** Controls how long a passkey authentication request stays active on the login page before timing out.

**How to use:** Enter the time limit in minutes. If sign-in verification is not completed within this timeframe, the user must restart the login attempt.

## **Enable User Verifications**

**What it does:** Enforces local device authorization (such as fingerprint verification, facial scan, or lock-screen PIN) whenever a passkey is used.

**How to use:** Keep this toggled **ON** to ensure physical user presence and local verification during every sign-in attempt.

Click **Save Changes** to immediately apply your updated configuration across your site, or click **Discard Changes** to undo uncommitted edits and reset back to your previously saved settings.

---
Source: https://docs.wpultimatesecurity.com/docs/biometric-login-passkey/passkey-settings/
