Installation
Prerequisites
- TYPO3 13.4 LTS or TYPO3 14.3 LTS
- PHP 8.2, 8.3, 8.4, or 8.5
netresearch/^0.6 (installed automatically)nr- passkeys- be - HTTPS is required for WebAuthn (except
localhostduring development) - A configured TYPO3 encryption key
(
$GLOBALS, minimum 32 characters)['TYPO3_ CONF_ VARS'] ['SYS'] ['encryption Key']
Installation via Composer
This is the recommended way to install the extension:
composer require netresearch/nr-passkeys-fe
This also installs netresearch/ as a dependency.
Activate the extension
After installation, activate the extension in the TYPO3 backend:
- Go to Admin Tools > Extensions
- Search for "Passkeys Frontend Authentication"
- Click the activate button
Or use the CLI:
vendor/bin/typo3 extension:activate nr_passkeys_fe
Note
If nr_ is not already active, activate it first.
Both extensions must be active for the frontend login to work.
Database schema update
The extension adds two tables and extends two core tables:
tx_-- Frontend passkey credentialsnrpasskeysfe_ credential tx_-- Bcrypt-hashed recovery codesnrpasskeysfe_ recovery_ code fe_-- Addsusers passkey_andgrace_ period_ start passkey_columns for enforcement trackingnudge_ until fe_-- Addsgroups passkey_andenforcement passkey_columns for per-group enforcementgrace_ period_ days
After activation, run the database schema update:
- Go to Admin Tools > Maintenance > Analyze Database Structure
- Apply the suggested changes
Or use the CLI:
vendor/bin/typo3 database:updateschema
Include TypoScript
Include the extension's TypoScript in your site configuration:
- Go to Site Management > TypoScript
- Edit your root TypoScript record
- Add the static template Passkeys Frontend Authentication (nr_passkeys_fe)
Or add it manually:
@import 'EXT:nr_passkeys_fe/Configuration/TypoScript/setup.typoscript'
@import 'EXT:nr_passkeys_fe/Configuration/TypoScript/constants.typoscript'
Add the plugins
Three frontend plugins are available. Add them to your pages as content elements:
- NrPasskeysFe:Login
- The passkey login form. Place on your login page. Supports both discoverable (usernameless) and username-first login.
- NrPasskeysFe:Management
- Self-service credential management. Place on a page accessible only to logged-in users.
- NrPasskeysFe:Enrollment
- Enrollment form used as the interstitial target. Required when enforcement is active.
See Quick Start for a step-by-step walkthrough.
Verify the installation
After activation:
- Visit the login page with the NrPasskeysFe:Login plugin. You should see a Sign in with a passkey button.
- The backend module Admin Tools > Passkey Management FE should appear.
Warning
HTTPS is mandatory for WebAuthn to function. The only exception
is localhost for local development. If TYPO3 is behind a
reverse proxy, ensure TYPO3_ or
[SYS] is set correctly.