Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Opensolr Search 4.5.0 Minor update available for module opensolr_search (4.5.0). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

drupal-mfa

3 sites No security coverage Drupal 9–11
View on drupal.org

This module provides two-factor and multi-factor authentication for Drupal using FIDO2/WebAuthn security keys and TOTP authenticator apps. Users can register hardware security keys, platform authenticators, passkeys, and authenticator apps for a secure login experience.

Description

Provides FIDO2/WebAuthn security key and TOTP authenticator app
support for two-factor (2FA) and multi-factor (MFA) authentication in Drupal.

Users can register hardware security keys (YubiKey, SoloKey, etc.), platform authenticators (Windows
Hello, Touch ID, Android biometrics), passkeys, and TOTP authenticator apps (Google Authenticator,
andOTP, FreeOTP, Aegis, etc.).

Features

  • WebAuthn/FIDO2 — register and authenticate with hardware security keys, platform
    authenticators, and passkeys
  • TOTP — set up authenticator apps with QR code provisioning
  • 2FA mode — any single configured method clears the gate
  • MFA mode — require all configured methods (e.g. both a security key and
    authenticator app)
  • Per-user toggle — users choose whether to enable 2FA (when policy is
    "optional")
  • Admin policy — set 2FA as optional or required for all users
  • 2FA gate — event subscriber blocks access to the site until verification is
    complete
  • Self-service management — users manage their own keys and TOTP at
    /user/{uid}/security-keys
  • Clone detection — flags authenticators with sign counter anomalies

Requirements

  • Drupal 9.2+ (compatible with Drupal 10 and 11)
  • PHP 7.4+
  • HTTPS (required by the WebAuthn browser API)

Installation

composer require drupal-mfa
  drush en webauthn

Configuration

  1. Go to /admin/config/people/webauthn
  2. Set Relying Party ID to your domain (e.g. example.com)
  3. Set Relying Party Name (shown in authenticator prompts)
  4. Choose Policy: optional or required
  5. Choose Verification Mode: any (2FA) or all (MFA)

Libraries

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Feb 2026
Latest release
6 months ago
Releases (12 mo)
2 ▲ from 0
Maintenance
Slowing

Releases

Version Type Core Release date
1.0.1 Stable 9–11 Feb 23, 2026
1.0.x-dev Dev 9–11 Feb 23, 2026