---
title: "Installation"
manual: "Passkeys Frontend Authentication"
version: "2.0"
permalink: "https://docs.typo3.org/permalink/netresearch/nr-passkeys-fe:installation@2.0"
source: "Installation/Index.rst"
rendered: "2026-09-29T22:18:36+00:00"
---

# Installation {#installation}

## Prerequisites {#prerequisites}

-   TYPO3 13.4 LTS or TYPO3 14.3 LTS
-   PHP 8.2, 8.3, 8.4, or 8.5
-   `netresearch/nr-passkeys-be` ^0.6 (installed automatically)
-   HTTPS is **required** for WebAuthn (except `localhost` during
    development)
-   A configured TYPO3 encryption key
    (`$GLOBALS['TYPO3_CONF_VARS']['SYS']['encryptionKey']`,
    minimum 32 characters)

## Installation via Composer {#installation-via-composer}

This is the recommended way to install the extension:

```bash
composer require netresearch/nr-passkeys-fe
```

This also installs `netresearch/nr-passkeys-be` as a dependency.

## Activate the extension {#activate-the-extension}

After installation, activate the extension in the TYPO3 backend:

1.  Go to **Admin Tools > Extensions**
1.  Search for "Passkeys Frontend Authentication"
1.  Click the activate button

Or use the CLI:

```bash
vendor/bin/typo3 extension:activate nr_passkeys_fe
```

> [!NOTE]
> If `nr_passkeys_be` is not already active, activate it first.
> Both extensions must be active for the frontend login to work.

## Database schema update {#database-schema-update}

The extension adds two tables and extends two core tables:

-   `tx_nrpasskeysfe_credential` -- Frontend passkey credentials
-   `tx_nrpasskeysfe_recovery_code` -- Bcrypt-hashed recovery codes
-   `fe_users` -- Adds `passkey_grace_period_start` and
    `passkey_nudge_until` columns for enforcement tracking
-   `fe_groups` -- Adds `passkey_enforcement` and
    `passkey_grace_period_days` columns for per-group enforcement

After activation, run the database schema update:

1.  Go to **Admin Tools > Maintenance > Analyze Database
    Structure**
1.  Apply the suggested changes

Or use the CLI:

```bash
vendor/bin/typo3 database:updateschema
```

## Include TypoScript {#include-typoscript}

Include the extension's TypoScript in your site configuration:

1.  Go to **Site Management > TypoScript**
1.  Edit your root TypoScript record
1.  Add the static template
    **Passkeys Frontend Authentication (nr_passkeys_fe)**

Or add it manually:

```typoscript
@import 'EXT:nr_passkeys_fe/Configuration/TypoScript/setup.typoscript'
@import 'EXT:nr_passkeys_fe/Configuration/TypoScript/constants.typoscript'
```

## Add the plugins {#add-the-plugins}

Three frontend plugins are available. Add them to your pages as
content elements:

-   **NrPasskeysFe:Login**

    The passkey login form. Place on your login page.
    Supports both discoverable (usernameless) and username-first login.

-   **NrPasskeysFe:Management**

    Self-service credential management. Place on a page accessible
    only to logged-in users.

-   **NrPasskeysFe:Enrollment**

    Enrollment form used as the interstitial target. Required when
    enforcement is active.

See [Quick Start](https://docs.typo3.org/permalink/netresearch/nr-passkeys-fe:quick-start@2.0) for a step-by-step walkthrough.

## Verify the installation {#verify-the-installation}

After activation:

1.  Visit the login page with the NrPasskeysFe:Login plugin.
    You should see a **Sign in with a passkey** button.
1.  The backend module **Admin Tools > Passkey Management FE**
    should appear.

> [!WARNING]
> HTTPS is mandatory for WebAuthn to function. The only exception
> is `localhost` for local development. If TYPO3 is behind a
> reverse proxy, ensure `TYPO3_SSL` or
> `[SYS][reverseProxySSL]` is set correctly.
