---
title: "User Management"
manual: "Passkeys Frontend Authentication"
version: "2.0"
permalink: "https://docs.typo3.org/permalink/netresearch/nr-passkeys-fe:administration-user-management@2.0"
source: "Administration/UserManagement.rst"
rendered: "2026-09-29T22:18:36+00:00"
---

# User Management {#administration-user-management}

Administrators can manage frontend user passkeys from the backend
module or via the `fe_users` record in the list module.

## Viewing credentials in fe_users {#viewing-credentials-in-fe-users}

When editing a `fe_users` record in **Web > List**, a
read-only info element shows:

-   Number of registered passkeys
-   Last used date
-   Enforcement level applicable to the user

This uses a custom TCA element (`passkey_fe_info`) registered
by the extension.

## Backend module actions {#backend-module-actions}

From **Admin Tools > Passkey Management FE**:

-   **List credentials**

    View all passkeys registered by a specific user.

-   **Revoke a credential**

    Immediately invalidate a specific passkey. The user must re-enroll
    from that device.

-   **Revoke all credentials**

    Remove all passkeys for a user. Use when a user's device is lost
    or stolen.

-   **Reset grace period**

    Clear the user's grace period start
    (`fe_users.passkey_grace_period_start` set to 0). While the user is
    under `required` enforcement without a passkey, the next page request
    starts a new grace period of the configured length. Changing the
    enforcement level or the grace period days does not restart a grace
    period; this action does.

-   **Unlock account**

    If the user's account is locked due to too many failed attempts,
    unlock it immediately.

## Invalidating passkeys via database {#invalidating-passkeys-via-database}

In an emergency, you can revoke all passkeys for a user directly:

```sql
-- View credentials
SELECT * FROM tx_nrpasskeysfe_credential
WHERE fe_user = <uid>;

-- Revoke all credentials for a user
UPDATE tx_nrpasskeysfe_credential
SET deleted = 1
WHERE fe_user = <uid>;

-- Or hard-delete
DELETE FROM tx_nrpasskeysfe_credential
WHERE fe_user = <uid>;
```

> [!WARNING]
> Direct database manipulation bypasses audit logging. Prefer using
> the backend module or admin API when possible.
